# I’ve received an email asking me to install a security patch

> The message looks like an official alert, it names a vulnerability and offers a file to install: this is exactly the scenario of a documented campaign against WooCommerce merchants, and the “patch” is the hack itself.

- Source canonique : [https://allaux.fr/en/securite/email-demande-installer-correctif-securite](https://allaux.fr/en/securite/email-demande-installer-correctif-securite)
- Langue : EN
- Dernière mise à jour : 2026-09-30

## Direct answer

> Install nothing. A legitimate update arrives through Dashboard then Updates, never as a .zip archive attached to or linked from an email. Check the announced vulnerability identifier against the vendor official channel: in this campaign it was invented. If the archive has already been uploaded, treat the site as compromised and handle it accordingly.

## What the message claims, and why it is false

The scenario is documented. On 23 April 2025, Patchstack published its analysis of an email campaign imitating an official WooCommerce security alert. The message announces a flaw called “Unauthenticated Administrative Access”, states that your shop is affected, and invites you to download a patch and install it yourself. That flaw does not exist: it was invented for the campaign. The file on offer is the hack.

The staging is restrained, which is exactly what makes it work: administrative tone, a credible-sounding flaw name, measured urgency rather than panic, a single download button. This is nothing like crude banking phishing, and experienced merchants do click. Patchstack links the campaign to the same actor behind a December 2023 operation, which already used a fabricated vulnerability identifier.

## What to check in thirty seconds

- The message names a flaw and asks you to download a file and install it yourself.
- The flaw name matches no advisory published in the vendor’s official channel.
- The link looks like the official domain, but one letter has been swapped for an accented character.
- The patch is presented as urgent while no update is offered in your own dashboard.
- The file is a plugin archive to upload by hand, not an update offered by the back office.

## Why the fake site’s address looks right

The link does not point at an obviously foreign domain. It points at one built through an IDN homograph attack: a letter of the legitimate name is replaced by a visually near-identical accented character. In an address bar, at browser font size, the difference is invisible. I am not reproducing the domain here.

The practical consequence matters more than the technique: “I looked at the address and it seemed fine” is not a defence against this campaign. The only reliable check is to not follow the link at all, and to open your own dashboard, or the vendor’s site, from a bookmark you saved yourself.

## I clicked the link but installed nothing

Opening the page does not compromise the shop. The mechanism Patchstack describes relies on you installing a plugin: until the file has been uploaded and activated in WordPress, the site has not been touched this way.

Two caveats, both worth acting on. If you typed administrator credentials into the page that opened, change them now and review recent back-office logins. If the file was downloaded to your computer, delete it without opening or unzipping it. Then run the checks below anyway: they take a few minutes and they settle the question, which beats living with an open one.

## The published indicators, in the order I check them

1. **A plugin folder with a telling name** — Look in wp-content/plugins/ for a folder named authbypass-update. That is the indicator Patchstack published for this campaign. Finding it settles the matter: treat the site as compromised and move straight to incident handling.
2. **A folder inside uploads** — In wp-content/uploads/, look for a folder whose name starts with wp-cached-. Nothing of that shape belongs among media library files.
3. **An administrator account with a random name** — The plugin creates an administrator account with a random eight-character name, then hides it from the user list. The dashboard list is therefore unreliable: compare it against the actual contents of the users table in the database.
4. **A scheduled task running every minute** — The campaign schedules a randomly named WP-Cron task that runs every minute. Minute-level scheduling is abnormal on an ordinary shop, and it is one of the few things still visible through a WP-Cron inspection tool.
5. **A plugin list you cannot trust** — The malicious plugin removes itself from the plugin list. Compare what the back office shows against the real contents of wp-content/plugins/ over SFTP or through your host’s file manager.
6. **What was dropped afterwards** — The payload downloads webshells from known families (P.A.S.-Fork, p0wny, WSO) and sends credentials and site information to remote servers. If any earlier indicator is present, assume every credential has leaked and rotate them all: WordPress administrators, FTP/SFTP, database, hosting account.

## The legitimate channel, and its limits

For a free plugin, an update arrives in the WordPress updates screen. For a paid one, it arrives through your account with the vendor, or automatically via the licence key registered on the site. There is no third route: no attachment, no archive sent by email, no direct download link in an unsolicited message.

That channel is not infallible either, and I would rather say so than sell a tidier rule. In June 2026, ShapedPlugin’s build and distribution infrastructure was compromised: several Pro versions were shipped with malicious code through the vendor’s own legitimate channel, with remediation starting on 16 June 2026 and publication on 22 June 2026. Only Pro versions were affected; the free versions on the WordPress.org repository were not. The lesson is not to distrust the official channel, but that watching your site’s files stays worthwhile even when you have done nothing unusual.

## The general rule that makes this campaign useless

> Neither WordPress nor WooCommerce ever asks you to download and install a patch by hand. Fixes ship as a new version through the official update channel. July 2026’s genuine security emergency shows what that looks like: WordPress 7.0.2, 6.9.5 and 6.8.6 were released on 17 July 2026, and WordPress.org enabled forced automatic updates on the affected versions. No attachment, no file to install yourself, no steps requested by email.

## If any indicator is present

- **What to do within two hours** — The order of operations right after discovering a compromise. ([/securite/que-faire-dans-les-deux-heures](/securite/que-faire-dans-les-deux-heures))
- **Checking whether my site is compromised** — The full review, beyond this campaign’s specific indicators. ([/securite/verifier-si-mon-site-est-compromis](/securite/verifier-si-mon-site-est-compromis))
- **My WordPress site has been hacked** — Handling a WordPress or WooCommerce site that is already compromised. ([/wordpress-woocommerce/site-pirate](/wordpress-woocommerce/site-pirate))
- **Admin passwords and shared access** — Which credentials to rotate, and in what order, after a leak. ([/securite/mots-de-passe-administration-acces-partages](/securite/mots-de-passe-administration-acces-partages))

## FAQ

### The email names a specific vulnerability. Doesn’t that make it legitimate?

No. The April 2025 campaign announced a flaw invented from scratch, and the same actor had already used a fabricated identifier in December 2023. A flaw name is verified in the vendor’s official channel, never in the message quoting it.

### I installed the file and then uninstalled it. Is that enough?

No. The plugin drops other files, creates a hidden administrator account and a scheduled task that all outlive it. Uninstalling removes only the visible part.

### How do I verify a message that appears to come from my vendor or host?

I never use the link in the message. I open the site dashboard and the vendor’s site from my own bookmarks and check whether the information is there. If it isn’t, the message is worthless.

### My site works normally. Does that rule out the risk?

No. The campaign is built to stay quiet: the plugin hides from the plugin list, the administrator account it creates is hidden too, and visitors see no change. No symptom is not proof.

### Should I change every password if an indicator is present?

Yes. The payload described sends credentials and site information to remote servers. I rotate WordPress administrator accounts, FTP/SFTP access, database credentials and the hosting account, then delete any account I cannot account for.
