Hacked shop or site? Find it, clean it, close the door
Card fraud reports, a Google warning, strange redirects or files you do not recognise. Your AI saves the evidence first, scans files, database and cron for what was planted, removes it with your approval, and changes every credential so it does not come back.
Works with Claude, Claude Code, ChatGPT and Cursor.
How your AI does it
- STEP 1
Evidence first
A snapshot of the site, /etc and the database, labelled with the date, before anything changes. Your AI works out when it started from customer reports, changed files and logs.
- STEP 2
Scan files, database and the system
malware_scan looks for PHP backdoors, eval of decoded data, PHP hidden in images and icons, card skimmers in Magento's core_config_data and CMS blocks, injected WordPress options and posts, and malicious cron entries. Then it checks the places malware hides to survive a cleanup: cron for every user, systemd timers, authorized_keys, new users, processes from /tmp.
- STEP 3
Find the way in
The web access logs around the first changed file usually show it: an outdated plugin or extension, a stolen admin login or an upload form.
- STEP 4
Contain and clean
Maintenance mode if a skimmer is stealing cards right now. Core is reinstalled from official sources rather than edited, injected database content and backdoors are removed with your approval, and the scan runs again until it is clean.
- STEP 5
Close it and rotate everything
Patch what was exploited, new passwords for admins, database and SSH users, new WordPress salts, payment provider keys if a skimmer was present, two-factor for admins, then the hardening playbook. The report tells you what you must do next, including your duties after card data was exposed.
What the cleanup looks for
- PHP backdoors and web shells, including obfuscated ones
- PHP hidden in .ico, image and media files
- Functions called by a name taken from the request
- Card skimmers in design/head/includes, footers and CMS blocks
- Recently changed JavaScript in pub/static and themes
- WordPress core and plugin files that fail their checksums
- curl | sh and similar entries in crontabs
- Unknown authorized_keys, users and systemd units
Tested on real servers
From our own test runs with Claude Code on fresh Rocky Linux 10 servers.
planted attacks found in a 40,000-file Mage-OS shop, with no false positives: PHP in media, PHP in an .ico, a hidden request-named call, a skimmer in the page head and a curl | sh cron
for a fresh AI session, told only "my shop was hacked", to fetch the cleanup playbook, snapshot first and start removing what it found
Start with this prompt
Paste it into your AI with SudoWhizzy connected. It fetches the matching playbook and explains its plan before changing anything.
My site was hacked: find it and clean it · all prompts
Pro and up for the malware scan. On Free your AI can still investigate read-only: logs, cron, users and suspicious files. Pricing.
Questions
Will it delete files without asking?
No. Removing files, database content, cron entries or keys each needs your approval, and a snapshot is taken before anything changes, so the evidence and the original state are kept.
Is a scan enough?
Rarely. Malware usually comes back through the hole it used and the persistence it left. That is why the cleanup includes finding the way in, patching it and changing every credential.
My card payments were skimmed. What else should I do?
Tell your payment provider, and check your legal duty to report a data breach where you operate. Your AI's report lists what was found, with paths and dates, which helps with both.
Can it watch for it coming back?
Yes. Ask for a weekly malware_scan, and on Pro and Agency SudoWhizzy also checks your sites every 15 minutes and emails you when one stops answering.
Safety on every task: destructive actions wait for your approval, /etc is saved before changes, and every action is logged. How it works.
More your AI can do
Your Magento server, run by your AI
WordPress and WooCommerceA fast, secure WordPress server, run by your AI
Fresh VPSFrom an empty VPS to a secure web server, by asking
HardeningHarden your Linux server without locking yourself out
MigrationMove your site to a new server with minutes of downtime
Connect your first server
Start free with one server in read-only mode. Upgrade when you want your AI to fix things.
Get started