Story perspectives
Malicious WordPress plugin steals credentials, crypto on FBI site
5/23/2026
1 of 1
Story summary
- A malicious WordPress plugin injected an infostealer that harvested credentials, cookies and crypto data.
- The plugin was delivered via FBI Director Kash Patel’s Apparel site, which was hacked and taken offline.
- Security researcher WifiRumHam reported the code also installed a payment skimmer on the checkout page.
- After user debbie flagged a modified Cloudflare verification page, the FBI declined to confirm an investigation and said Patel had divested before becoming director.
