Please advise the following:
What distro are you running CWP on?
What web server are you using? Apache or Nginx?
The version of web server?
What PHP version?
Was the affected site using WordPress?
If so, what version?
Sure, here are the details:
1.
Operating System: CentOS 7
2.
Web Server: Nginx & Apache
Additional Options:
php-cgi/suPHP, nginx/php-fpm, apache/php-fpm, proxy
3.
Web Server Versions: Apache 2.4.57
suPHP 0.7.2
Nginx 1.26.1
4.
PHP Version: The default PHP version is 7.4.33, but all websites are running PHP 8.3.21.
5.
Affected Websites: There are approximately 20 websites on this server.
The affected websites included:
* 2 WordPress websites
* 1 HTML website
* 5 custom-built websites
* Several subdomains
So this was not limited to WordPress websites.
6.
WordPress Versions:The two affected WordPress installations were:
* WordPress 6.8.8 — updated on August 12 at 17:52:28
* WordPress 6.9.7 — updated on August 12 at 19:19:48
For comparison, the following WordPress installations on the same server were not affected:
* WordPress 7.0.4 — updated on August 12 at 18:03:26
* WordPress 7.0.4 — updated on August 12 at 18:39:09
* WordPress 7.1 — updated on August 20 at 02:52:42
* WordPress 7.1 — updated on August 20 at 12:19:19
* WordPress 7.1 — updated on August 24 at 10:26:25
The malicious modifications were observed on August 13, while the affected WordPress installations had already been updated on August 12.
Also, since non-WordPress and custom websites were affected as well, I believe there may be another common attack vector involved.
One additional point: this is a private server and nobody other than myself has access to it.
I also noticed that the modification timestamps of the affected files were identical. This was not limited to the jQuery files of a single website; the jQuery files across the other affected websites had the same modification time as well. This makes me suspect that the modification may have been triggered from a single point and then propagated to other websites.
The WordPress installations initially looked suspicious, but the other affected websites use completely different custom infrastructures, and some of them do not even have an administrative panel. Therefore, it would not be possible to inject the code through those websites themselves.
I would also like to ask other CWP users, especially those running
AlmaLinux 9 with all current updates, to check their jQuery files for the same injection. If this is a CWP-related issue, checking different operating systems and fully updated CWP installations may help identify the common attack vector.