The first clue did not explain the whole event.
An unfamiliar PHP file in a web-accessible path prompted an evidence-preserving investigation. Its behaviour was consistent with a command-capable web shell, so Osiris expanded the scope beyond deleting one file. WordPress core verification passed, but that result addressed only the application distribution—not the trustworthiness of the server beneath it.
Process, network, filesystem, and service review revealed an active cryptocurrency miner, outbound mining activity, a second payload location, and an operating-system service designed to restore the workload automatically. Related artifacts predated the newest visible clue, expanding the likely exposure window. Publicly reachable administrative services further increased consequence. Together, the evidence established an active server-level compromise rather than an isolated WordPress anomaly.
