New WordPress Malware Uses Steam Profile Comments to Hide C2 Instructions

https://hackread.com/wp-content/uploads/2026/06/wordpress-malware-steam-profile-comments-instructions-2-1024x576.png

A new WordPress malware campaign has been found using an unusual hiding place for its command instructions: Steam Community profile comments. According to research published by GoDaddy Security, the malware stores encoded data inside comments on Steam profiles, then uses infected WordPress sites to fetch and decode that data during normal page activity.

The method allows attackers to place command-and-control data on a trusted public platform without hosting an obvious malicious server. GoDaddy said the campaign was first detected in July 2025 and has been seen on about 1,980 WordPress sites. The affected sites load external JavaScript for visitors and also contain a backdoor that can modify PHP files on the site.

According to GoDaddy’s technical blog post, once planted, the malware can pull hidden instructions from Steam, inject a remote script into public pages, and keep a server side access path available for future changes. That combination gives...

Copyright of this story solely belongs to hackread.com. To see the full text click HERE

Read more