Malware

Eval atob

Eval atob is a JavaScript pattern where a base64 string is decoded with `atob()` and then run with `eval()` or `Function()`. It hides the real code from a quick read and from simple scanners.

How it is measured

Search script text for `eval(atob(`, `Function(atob(`, or `eval(unescape(`. Decode the base64 string and read the result: it commonly holds a redirect, an iframe injector, or a loader that fetches more code. Your editor, a browser console, or `base64 -d` is enough.

Count occurrences per file. One in a minified library may be legitimate. One in a theme's `footer.php`, with a 4,000-character string, is not.

Worked example

A site owner notices their page flashes to a casino site on mobile only. Searching the theme turns up `<script>eval(atob('dmFyIHU9bmF2aWdhdG9yLnVzZXJBZ2VudDtpZih1Lm1hdGNoKC9BbmRyb2lk...'))</script>` in the header. Decoding it reveals a check for mobile user agents followed by `location.href = 'https://win-prize.top'`.

Removing the tag stops the redirect. The owner then looks for what added it, finding an outdated slider plugin.

How it differs

Eval atob hides code by encoding it, while a packer shrinks and scrambles it by other means such as Dean Edwards style compression. Obfuscation is the general idea of making code hard to read. Eval atob is easy to undo, but it is a very reliable signal because honest code rarely needs to hide.

Common errors

Deleting the tag without finding how it got in. Assuming all base64 is bad when images use it too. Missing the variants that use `String.fromCharCode` or hex escapes. Running the decoded code to see what happens. Grepping only the theme and not the database.

In practice

Search your theme files, plugins, and database option values for `eval(`, `atob(`, and `fromCharCode`. Decode each hit in a text editor, never in a browser on a real account. Remove the injection, update what let it in, and rescan.

See also

Obfuscation, Packer

Sources

Count this on a real site.

Watch my website