Hacked site

Hacked shop or site? Find it, clean it, close the door

Card fraud reports, a Google warning, strange redirects or files you do not recognise. Your AI saves the evidence first, scans files, database and cron for what was planted, removes it with your approval, and changes every credential so it does not come back.

Works with Claude, Claude Code, ChatGPT and Cursor.

How your AI does it

  1. STEP 1

    Evidence first

    A snapshot of the site, /etc and the database, labelled with the date, before anything changes. Your AI works out when it started from customer reports, changed files and logs.

  2. STEP 2

    Scan files, database and the system

    malware_scan looks for PHP backdoors, eval of decoded data, PHP hidden in images and icons, card skimmers in Magento's core_config_data and CMS blocks, injected WordPress options and posts, and malicious cron entries. Then it checks the places malware hides to survive a cleanup: cron for every user, systemd timers, authorized_keys, new users, processes from /tmp.

  3. STEP 3

    Find the way in

    The web access logs around the first changed file usually show it: an outdated plugin or extension, a stolen admin login or an upload form.

  4. STEP 4

    Contain and clean

    Maintenance mode if a skimmer is stealing cards right now. Core is reinstalled from official sources rather than edited, injected database content and backdoors are removed with your approval, and the scan runs again until it is clean.

  5. STEP 5

    Close it and rotate everything

    Patch what was exploited, new passwords for admins, database and SSH users, new WordPress salts, payment provider keys if a skimmer was present, two-factor for admins, then the hardening playbook. The report tells you what you must do next, including your duties after card data was exposed.

What the cleanup looks for

  • PHP backdoors and web shells, including obfuscated ones
  • PHP hidden in .ico, image and media files
  • Functions called by a name taken from the request
  • Card skimmers in design/head/includes, footers and CMS blocks
  • Recently changed JavaScript in pub/static and themes
  • WordPress core and plugin files that fail their checksums
  • curl | sh and similar entries in crontabs
  • Unknown authorized_keys, users and systemd units

Tested on real servers

From our own test runs with Claude Code on fresh Rocky Linux 10 servers.

5 of 5

planted attacks found in a 40,000-file Mage-OS shop, with no false positives: PHP in media, PHP in an .ico, a hidden request-named call, a skimmer in the page head and a curl | sh cron

~3 min

for a fresh AI session, told only "my shop was hacked", to fetch the cleanup playbook, snapshot first and start removing what it found

Start with this prompt

Paste it into your AI with SudoWhizzy connected. It fetches the matching playbook and explains its plan before changing anything.

Using SudoWhizzy, I think my site was hacked. Follow the malware-cleanup playbook (get_playbook): take an evidence snapshot first, run malware_scan and read what it finds, check the database, cron and logs. Explain what you find before removing anything, and ask me before taking the site down. At the end, tell me what you removed, how they probably got in, and exactly what I still need to do (passwords, payment provider, Google).

My site was hacked: find it and clean it · all prompts

Which plan

Pro and up for the malware scan. On Free your AI can still investigate read-only: logs, cron, users and suspicious files. Pricing.

Questions

Will it delete files without asking?

No. Removing files, database content, cron entries or keys each needs your approval, and a snapshot is taken before anything changes, so the evidence and the original state are kept.

Is a scan enough?

Rarely. Malware usually comes back through the hole it used and the persistence it left. That is why the cleanup includes finding the way in, patching it and changing every credential.

My card payments were skimmed. What else should I do?

Tell your payment provider, and check your legal duty to report a data breach where you operate. Your AI's report lists what was found, with paths and dates, which helps with both.

Can it watch for it coming back?

Yes. Ask for a weekly malware_scan, and on Pro and Agency SudoWhizzy also checks your sites every 15 minutes and emails you when one stops answering.

Safety on every task: destructive actions wait for your approval, /etc is saved before changes, and every action is logged. How it works.

Connect your first server

Start free with one server in read-only mode. Upgrade when you want your AI to fix things.

Get started