You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

WordPress网站遭JS恶意脚本感染,求SSH批量删除受感染文件方法

How to Batch Remove/Clean WordPress Files Infected with Malicious JS via SSH

Hey there, sorry to hear your WordPress site got hit by this malicious JS script—dealing with thousands of infected files is stressful, but let’s work through this systematically using SSH.

Step 1: First, Confirm All Infected Files

Before deleting anything, we need to accurately identify every file that contains the malicious code to avoid accidental data loss.

Your malicious script has unique markers we can search for, like the variable _0xaae8 or the obfuscated domain js.yreuqj. Use the grep command to recursively scan your WordPress root directory and list all infected files:

# Recursively search for the unique variable and output only file paths
grep -rl "_0xaae8" /path/to/your/wordpress/root > infected_files.txt
  • -r: Recursively scan all subdirectories
  • -l: Only output the names of files containing the match
  • The output is saved to infected_files.txt so you can review it first—open this file to verify no legitimate files are incorrectly flagged.

Pro tip: If you want to preview the malicious code in each file before acting, use:

grep -B2 -A2 "_0xaae8" /path/to/your/wordpress/root

This shows 2 lines before and after the matched code.

Step 2: Backup Infected Files (Critical!)

Never delete files without a backup. Create a compressed archive of all infected files to restore if something goes wrong:

tar -czf infected_files_backup.tar.gz -T infected_files.txt

Store this backup somewhere safe (not on the server).

Step 3: Batch Delete Infected Files

If you’re certain these files are fully compromised (e.g., they’re not core WordPress files, themes, or plugins you need), use xargs to delete them in bulk:

xargs rm -f < infected_files.txt
  • -f: Force deletion without confirmation prompts

Alternative: Clean the Malicious Code Instead of Deleting

If some infected files are legitimate (like theme template files or plugin scripts), you can remove only the malicious code instead of deleting the whole file. Use sed to strip out the malicious lines:

For Linux systems:

xargs sed -i '/var _0xaae8=\["","\\x6A\\x6F\\x69\\x6E"/d' < infected_files.txt

For macOS systems (note the empty '' flag for -i):

xargs sed -i '' '/var _0xaae8=\["","\\x6A\\x6F\\x69\\x6E"/d' < infected_files.txt

This command deletes any line starting with the malicious variable declaration from all infected files.

Step 4: Secure Your Site to Prevent Future Infections

Once you’ve cleaned up, take these steps to stop the malware from returning:

  • Update WordPress core, all themes, and plugins to their latest versions (outdated software is the #1 entry point for malware)
  • Audit all admin accounts—delete any suspicious accounts and use strong, unique passwords for remaining ones
  • Set proper file permissions: WordPress directories should be 755, files should be 644 (avoid 777 at all costs)
  • Install a security plugin (like Wordfence or Sucuri) to run regular scans and block malicious traffic
  • Enable automatic updates for WordPress core, themes, and plugins to stay protected against new vulnerabilities

内容的提问来源于stack exchange,提问作者isko flores

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.15 07:39:39