Porn Sites Use SVG Files to Spread Malicious Script, Hijacking Facebook Likes

2025-08-10
Porn Sites Use SVG Files to Spread Malicious Script, Hijacking Facebook Likes

Security researchers have discovered multiple pornographic websites built on WordPress that use SVG files to spread malicious JavaScript code. This obfuscated code ultimately downloads a malicious script called Trojan.JS.Likejack, which silently likes specified Facebook posts if the user is logged in. This isn't a new tactic; previous incidents involved SVGs in cross-site scripting attacks and phishing scams. Researchers have identified dozens of affected websites. While Facebook shuts down accounts involved, these offenders consistently return with new profiles.

Tech