malware WordPress malware campaign hides payloads in Steam profiles A WordPress malware campaign has infected nearly 2,000 websites by hiding command-and-control (C2) data within Steam Community profile comments. The attackers utilize invisible Unicode characters to encode malicious payloads, bypassing traditional detection methods and leveraging Valve's platform for C2. This campaign… BleepingComputer · Jun 1, 2026 High USwordpresssteemunicode