WordPress网站遭JS恶意脚本感染,求SSH批量删除受感染文件方法
Hey there, sorry to hear your WordPress site got hit by this malicious JS script—dealing with thousands of infected files is stressful, but let’s work through this systematically using SSH.
Step 1: First, Confirm All Infected Files
Before deleting anything, we need to accurately identify every file that contains the malicious code to avoid accidental data loss.
Your malicious script has unique markers we can search for, like the variable _0xaae8 or the obfuscated domain js.yreuqj. Use the grep command to recursively scan your WordPress root directory and list all infected files:
# Recursively search for the unique variable and output only file paths grep -rl "_0xaae8" /path/to/your/wordpress/root > infected_files.txt
-r: Recursively scan all subdirectories-l: Only output the names of files containing the match- The output is saved to
infected_files.txtso you can review it first—open this file to verify no legitimate files are incorrectly flagged.
Pro tip: If you want to preview the malicious code in each file before acting, use:
grep -B2 -A2 "_0xaae8" /path/to/your/wordpress/root
This shows 2 lines before and after the matched code.
Step 2: Backup Infected Files (Critical!)
Never delete files without a backup. Create a compressed archive of all infected files to restore if something goes wrong:
tar -czf infected_files_backup.tar.gz -T infected_files.txt
Store this backup somewhere safe (not on the server).
Step 3: Batch Delete Infected Files
If you’re certain these files are fully compromised (e.g., they’re not core WordPress files, themes, or plugins you need), use xargs to delete them in bulk:
xargs rm -f < infected_files.txt
-f: Force deletion without confirmation prompts
Alternative: Clean the Malicious Code Instead of Deleting
If some infected files are legitimate (like theme template files or plugin scripts), you can remove only the malicious code instead of deleting the whole file. Use sed to strip out the malicious lines:
For Linux systems:
xargs sed -i '/var _0xaae8=\["","\\x6A\\x6F\\x69\\x6E"/d' < infected_files.txt
For macOS systems (note the empty '' flag for -i):
xargs sed -i '' '/var _0xaae8=\["","\\x6A\\x6F\\x69\\x6E"/d' < infected_files.txt
This command deletes any line starting with the malicious variable declaration from all infected files.
Step 4: Secure Your Site to Prevent Future Infections
Once you’ve cleaned up, take these steps to stop the malware from returning:
- Update WordPress core, all themes, and plugins to their latest versions (outdated software is the #1 entry point for malware)
- Audit all admin accounts—delete any suspicious accounts and use strong, unique passwords for remaining ones
- Set proper file permissions: WordPress directories should be
755, files should be644(avoid777at all costs) - Install a security plugin (like Wordfence or Sucuri) to run regular scans and block malicious traffic
- Enable automatic updates for WordPress core, themes, and plugins to stay protected against new vulnerabilities
内容的提问来源于stack exchange,提问作者isko flores

