Threat hunters have identified a rogue WordPress plugin capable of creating fake administrator users and injecting malicious JavaScript code to steal credit card information. The plugin, part of a Magecart campaign targeting e-commerce sites, replicates itself into must-use plugins, conceals its presence, and also includes an option to create hidden admin accounts. The campaign’s objective is to inject credit card-stealing malware into checkout pages and transmit the data to a hacker-controlled domain.

Mustang Panda Uses SnakeDisk USB Worm and Toneshell Backdoor to Target Air-Gap Systems – gbhackers.com
Mustang Panda Uses SnakeDisk USB Worm and Toneshell Backdoor to Target Air-Gap Systems gbhackers.com