Bacon / BaconQrCode

QR Code Generator for PHP
BSD 2-Clause "Simplified" License
1.83k stars 208 forks source link

possible infection in "Modules.php" file #109

Closed Kali-Gula closed 2 years ago

Kali-Gula commented 2 years ago

Hello, I would like to ask if in your source code there is a file called "Modules.php" A colleague tells me that on his website, passing wordfence, a path appears: "wp-content / mu-plugins / nue / vendor / bacon / bacon-qr-code / Modules.php" detected as malware.

I have downloaded your .zip and I don't see that it has that file. This installation is normal in mu-plugins / nue

Thansk

DASPRiD commented 2 years ago

BQC v1 had a Module.php, but no Modules.php: https://github.com/Bacon/BaconQrCode/blob/1.0.3/Module.php

Kali-Gula commented 2 years ago

Ok, I'll delete the file then. Do you want me to send you a .zip with the infected plugin for you to review? I say it because it goes like your name and developer. Thanks

DASPRiD commented 2 years ago

You could put the source code in a gist and link it here, sure.

Kali-Gula commented 2 years ago

I don't know how to do it. If you explain maybe

DASPRiD commented 2 years ago

Just go to https://gist.github.com/, there you can paste the source of that file.

Kali-Gula commented 2 years ago

vendor.zip I don't know if it's ok here

DASPRiD commented 2 years ago

Yeah, that's definitely malware.

Kali-Gula commented 2 years ago

OK, THANKS its inside "wp-content/mu-plugins". Called "nue"... Can you know where it comes from ? or how install it ? nue.zip Do you think I can DELETE all the mu-plugin directory if I don't use it.

DASPRiD commented 2 years ago

I have no idea.

Kali-Gula commented 2 years ago

OK, Really THANKS ! ;)