The publisher's site had been flagged by Google for serving malware, but every security audit returned clean. The team was frustrated - their WordPress dashboard looked fine, no suspicious activity, no strange files.

The malware was injected through a legitimate but compromised commercial plugin that passed all automated checks. It loaded only for certain user-agent strings and geographical locations, making it invisible to most scanners. The fix required deep file-level forensics.

Obfuscated malware in commercial plugin
Threat found
Conditional by user-agent & geo
Detection evasion
Cleared after cleanup
Google Safe Browsing
Zero downtime during recovery
Site traffic impact

A media publisher's high-traffic WordPress site had a clean bill of health from multiple security scans - yet was still serving malicious redirects to visitors. The dashboard showed no signs of compromise. No unauthorized admin users. No suspicious files detected by standard scanners. Yet the site was actively harming readers.

Malware hidden in a legitimate commercial plugin - invisible to standard scanners
Conditional payload delivery by user-agent and geography evaded detection
Deep file-level forensics identified the injection point
Cleanup without disrupting a high-traffic publishing operation
Post-recovery hardening to prevent future compromise
WordPresssecuritymalware recoveryforensicsplugin audit