Porn Sites Use SVG Files to Spread Malicious Script, Hijacking Facebook Likes
2025-08-10

Security researchers have discovered multiple pornographic websites built on WordPress that use SVG files to spread malicious JavaScript code. This obfuscated code ultimately downloads a malicious script called Trojan.JS.Likejack, which silently likes specified Facebook posts if the user is logged in. This isn't a new tactic; previous incidents involved SVGs in cross-site scripting attacks and phishing scams. Researchers have identified dozens of affected websites. While Facebook shuts down accounts involved, these offenders consistently return with new profiles.
Tech