Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

Sucuri reported that its SiteCheck scanner detected Sign1 malware on more than 39,000 websites over the six months preceding its April 2024 analysis. That is a historical detection count—not a current 2026 total—and the campaign targeted WordPress sites with injected scripts that could redirect selected visitors to scam pages.

What is Sign1 malware?

Sign1 is the internal campaign name used by Sucuri and GoDaddy Infosec for a series of malicious JavaScript injections targeting WordPress websites. Sucuri observed related activity beginning in 2023. The scripts were designed to behave selectively: depending on the visitor and the circumstances, they could send people through redirect infrastructure to scam pages, including pages that display fake “verify you’re not a robot” prompts.

In its April 2024 Sign1 analysis, Sucuri said SiteCheck had detected the campaign on more than 39,000 sites over the previous six months. This is a period-specific scanner count, not an estimate of how many sites are infected now.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How many sites did Sucuri report detecting?

Sucuri later published additional Sign1 counts for different reporting windows. The figures should be read with their time periods and detection context attached: they are not a single cumulative total or directly interchangeable measurements.

Reporting period Reported detections Context
Six months preceding Sucuri’s April 2024 analysis More than 39,000 sites SiteCheck’s headline-period detection count in the campaign write-up.
First half of 2024 56,999 infected websites Sucuri said these detections represented 12.05% of malware injections in that reporting period.
2024 96,084 detected infections Sucuri’s annual count covers a broader reporting window than the first-half figure.

The later figures are reported in Sucuri’s 2024 hacked website threat report. The report describes SiteCheck as an external scanner that simulates a typical visitor. That observation differs from hands-on server-side incident analysis, which can reveal how malicious code was added or where it is stored. The cited counts establish historical detections; they do not establish Sign1’s activity level in 2026.

How Sign1 infected WordPress sites

Scripts were added through widgets or code-insertion plugins

Sucuri’s analysis found Sign1 JavaScript injected into WordPress custom HTML widgets or added through legitimate code-insertion plugins, including Simple Custom CSS and JS. Because WordPress can store widget or plugin content in its database, the malicious code may not appear in the server files a file-only scanner checks.

Obfuscation and short-lived URLs complicated detection

The analyzed variants combined obfuscation and XOR encoding with dynamically generated URLs based on hexadecimal timestamps. Sucuri described those URLs as having a validity window of roughly ten minutes. This made the destination change over time and could make suspicious behavior harder to reproduce during a later check.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Redirects depended on visitor conditions

The scripts could check a visitor’s referrer and execute only for selected traffic, such as people arriving from Google or Facebook. Singapore’s Cyber Security Agency said the malware checked whether visitors came from reputable sites “such as Google, Facebook, and Instagram, to evade detection.” As a result, one visitor might see normal content while another sees a redirect; not every visit necessarily triggered the scam page.

How to check whether a WordPress site is redirecting visitors

Because Sign1 could filter by referrer and store injected content in the database, a normal visit or a scan limited to files may not reveal every part of an infection. Treat an intermittent redirect as a reason to investigate both what visitors receive and the WordPress content and settings that can inject scripts.

  • Check the site from more than one browser or device, and note whether the visit came from a search or social link. Do not assume a clean result from one visit rules out selective behavior.
  • Review custom HTML widgets and code-insertion plugins, including their saved content, for scripts or changes you cannot account for.
  • Inspect database-backed WordPress content as well as server files. A file-only check can miss code stored in widgets or plugin-managed content.
  • If a redirect appears or unfamiliar code is found, involve a qualified WordPress administrator or incident-response specialist to investigate the site’s database, files, and administrative access. A scan can help identify symptoms, but it should not be treated as proof that every infection component has been removed.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How to reduce the risk of a similar WordPress compromise

The Cyber Security Agency of Singapore’s March 27, 2024 advisory says attackers gained access through brute-force attacks or vulnerable plugins, then embedded scripts in widgets or legitimate plugins. It recommends several defenses for WordPress users and administrators:

  • Use strong, unique passwords and enable multi-factor authentication (MFA) for accounts that can manage the site.
  • Restrict login access by IP where practical, use CAPTCHA, and limit repeated login attempts to make automated guessing harder.
  • Keep WordPress core, plugins, and themes updated to address known vulnerabilities.

These measures reduce exposure; they do not guarantee prevention and are not a cleanup procedure for a site that is already compromised. A hardware security key is one physical way to implement MFA, but the advisory recommends MFA generally and does not endorse a particular product.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.