MALWARE detected in fusioncharts

Just got email from my hosting provider about potential malware (included in fusioncharts third lib)
Is it safe?

Malware has just been found on your website.
Malware refers to pieces of code designed to cause damage to your website or to misuse your hosting, for example, by sending spam in your name.

The malware detected is as follows:

File Malware type
subsites/lib/prod/third/fusioncharts-suite-xt/js/fusioncharts.events.js {YARA}ELCEEF_HTML_Smuggling_A
subsites/lib/prod/third/fusioncharts-suite-xt/js/fusioncharts.js {YARA}ELCEEF_HTML_Smuggling_A

To prevent further issues, we recommend taking action as soon as possible by removing the malware.
Additionally, it is advisable to change the passwords for your website and to update your CMS (such as WordPress), plugins, and theme to the latest versions to avoid recurrence.

PT version
Malware foi recentemente encontrado no seu site plansis.com.
Malware são trechos de código criados para causar danos ao seu site ou para explorar sua hospedagem, por exemplo, enviando spam em seu nome.

O malware detectado é o seguinte:

Arquivo Tipo de Malware
subsites/lib/prod/third/fusioncharts-suite-xt/js/fusioncharts.events.js {YARA}ELCEEF_HTML_Smuggling_A
subsites/lib/prod/third/fusioncharts-suite-xt/js/fusioncharts.js {YARA}ELCEEF_HTML_Smuggling_A

Para evitar novos problemas, recomendamos que você tome providências o mais rápido possível removendo o malware.
Além disso, é aconselhável alterar as senhas do seu site e atualizar sua instalação de CMS (como WordPress), bem como os plugins e temas, para as versões mais recentes a fim de prevenir recorrências.

I scanned both files but I don’t see any problem - if anyone suspects a file, they can test it here: VirusTotal

The only thing I could find is https://github.com/fusioncharts/fusioncharts-dist/issues/71

Not sure what the status is. Scanners are only for known vulnerabilities, always good to keep track of sites publishing these.

1 Like

thank you for checking. it seems third part libraries dot not get patched that often, i wonder if could get more control over thirdpart libraries in the future , like manual update, turn on/off in the deployment.
a huge pdf library takes 3/4 of the prod :slight_smile: , we do not use it , perhaps as many others.

thirdpart libraries is a vulnerability to get hacked, i think SC should take a serious look at it.

I agree. But it isn’t easy, especially if you depend on an open-source/external community maintaining the software.

tuve el mismo problema,
con FileZilla pude subir mi aplicación al servidor Cpanel…