Website support, maintenance and fixes for UK businessesCall 0208 088 8371info@websupportservices.co.uk

HomeWordPress malwareFake browser update malware cleanup for WordPress

Fake browser update malware cleanup for WordPress

Fake browser update malware makes a compromised website display a bogus Chrome, Firefox or similar update message that can trick visitors into downloading an unknown file. If the message comes from your WordPress site rather than the browser's genuine update mechanism, treat the website as compromised.

Signs you might see

  • Pop-up telling visitors to update Chrome or Firefox
  • Download of an unknown file
  • Injected script in page headers

Not sure? Run our free WordPress security scanner for a quick outside check.

What is fake browser update malware?

Fake browser update malware is a form of deceptive content placed on or loaded through a compromised website. The page imitates a browser or software warning and attempts to persuade the visitor to download a file or take another unsafe action.

Google classifies pages that pretend to be a trusted entity in order to make somebody perform a dangerous action as social engineering. Its guidance specifically includes deceptive content that encourages visitors to download unwanted software.

On WordPress, the visible warning may be generated by injected JavaScript, a modified theme or plugin, database content or a remote resource loaded into an otherwise legitimate page. Attackers can also make the behaviour conditional. The site owner may see the normal website while another device or visitor is shown the false update.

Do not download or open the file offered by the fake message as part of your investigation.

How to check a site showing fake browser updates

Record the affected URL and the circumstances in which the message appeared. Check the page from a different device, including a phone, but do not interact with suspicious download buttons. If the issue was reported by a customer, note whether they arrived from Google or another referring site.

Open Google Search Console and review Security Issues. Google says deceptive or social-engineering content detected on a site can be reported there. Check the Pages report as well for URLs you did not create and review property ownership for unfamiliar verified users.

Inspect the affected page source and loaded scripts for resources you do not recognise, especially additions to page headers or files that have changed unexpectedly. Compare WordPress core with trusted originals and inspect plugins and themes rather than limiting the check to visible page content. Review the database for unfamiliar scripts or values that could be inserted into page output.

Our free WordPress security scanner can provide an additional outside view of the site, but it should not replace file, database and hosting checks when visitors have seen a malicious download prompt.

How to remove fake browser update malware

  1. Take a full copy first. Preserve all WordPress files and the database and keep the infected copy for investigation and evidence.
  2. Secure the accounts. Change WordPress, hosting, database and FTP or SFTP passwords. Replace the WordPress salts in wp-config.php and remove unauthorised users.
  3. Find the injected code. Trace the false update prompt to the script, database record, plugin, theme or configuration that generates or loads it.
  4. Restore clean code. Replace compromised WordPress core and legitimate plugin or theme files with clean copies where appropriate and remove malicious database content.
  5. Look for secondary access. Check for backdoors and other altered files rather than stopping after the popup disappears.
  6. Close the original entry point. Patch or remove vulnerable software and secure any account or hosting access that was compromised.

After cleaning, test the conditions that previously displayed the fake update and recheck Search Console. Our Hacked Site Rescue is £349 fixed price.

How to reduce the risk of another fake update infection

Keep WordPress core and actively used plugins and themes updated. Delete extensions you no longer need rather than merely deactivating them, particularly when they are no longer maintained.

Use strong unique passwords, enable two-factor sign-in where available and limit administrator privileges to people who need them. File integrity checks are useful for spotting unexpected changes to scripts and PHP files between legitimate releases.

Keep complete off-server backups containing both files and the database. Continue monitoring Search Console and investigate new security warnings promptly.

Care plans start from £59 a month and include weekly updates, daily off-server backups, uptime monitoring and security scanning. More information is available on our WordPress maintenance page.

Common questions

Answers to the questions we hear most about this.

Why is my website telling visitors to update Chrome or Firefox?

If the message is being generated by the website rather than the browser's genuine update system, the site may contain injected deceptive content. Treat unexpected download prompts as a security incident and investigate the WordPress files, database and hosting environment.

Should I download the file from a fake browser update popup to inspect it?

No. Do not download or execute an unknown file offered by a suspicious website prompt. Preserve evidence from the website itself and investigate the source of the injected message instead.

Why does the fake update appear for some visitors but not for me?

Malicious content can be served conditionally according to factors such as device, referrer or user agent. Test from more than one context and use Search Console and server-level investigation rather than relying on your own normal browser visit.

Think your site has been hacked?

Hacked Site Rescue is a fixed £249. We remove the malware, close the way in and help clear the warnings.

Get website support