Updated The European website of TechCrunch (eu.techcrunch.com), one of the world’s most popular blogs, appears to have fallen victim to hackers, who have planted a malicious script on their site, designed to infect unsuspecting visitors.
TechCrunch Europe posted a message on its Twitter feed earlier today describing warnings about malware being distributed via the site as “annoying”. Perhaps a rather unusual turn of phrase, which might suggest to observers that the warnings were erroneous rather than the result of a serious security problem.
A closer examination of TechCrunch Europe’s site reveals that the offending code – which uses a malicious iFrame – is found in a JavaScript file, used by the site as part of its WordPress infrastructure. This attempts to serve up a malicious PDF file, exploiting a vulnerability that brings to your…
Read more in my article on the Naked Security website.
Found this article interesting? Follow Graham Cluley on Twitter, Mastodon, or Threads to read more of the exclusive content we post.