Nulled WordPress Themes Ruined Me

Joined
Mar 5, 2017
Messages
117
Reaction score
24
I was making a website and as usual I downloaded a bunch of nulled WP themes, some I got from BHW, some from Deleted member 752298 and some via Googleing. And check all of them on VirusTotal.

Well after a few days, there was a huge transaction on my credit card, kept getting e-mails about people accessing my g-mail accounts. I was able to recover some, but I lost my reddit, discord, multiple twitter accounts, had to change all the credit cards. FML.... my reddit and twitter profiles are now spamming Crypto LOL.....

How do I not make the same mistake again? I know, I know, don't download random shit. But other than that, is there something better than VirusTotal?
 
Last edited:
This is what i do i use the plugins and themes that i bought, use the plugins that are free and
use the nulled plugins only if i can use it and delete it , on money sites. Like link whisper.
For test sites anything goes.
Hope this helps.
 
Last edited:
I was making a website and as usual I downloaded a bunch of nulled WP themes, some I got from BHW, some from Deleted member 752298 and some via Googleing. And check all of them on VirusTotal.

Well after a few days, there was a huge transaction on my credit card, kept getting e-mails about people accessing my g-mail accounts. I was able to recover some, but I lost my reddit, discord, multiple twitter accounts, had to change all the credit cards. FML.... my reddit and twitter profiles are now spamming Crypto LOL.....

First of all, I am really sorry to read that you had a bad experience using a bunch of nulled WordPress themes and that you lost important access to your social media accounts.
I feel the pain bro. Using nulled themes and plugins from foreign sources can be a huge risk for your WordPress website.

We have been in the GPL market since 2018 and I have been developing WordPress websites for over 15 years now.
As this topic has been forwarded by several of our customers (half of BHW is using our services) I felt it was the right choice to leave a personal reply here.

Since we have been providing/sharing many WordPress clean and original WordPress themes and plugins here on BHW, and on our own website repository, it's impossible that we're part of this scam.
As other members suggested, the VirusTotal Report is very limited. However, you can rest assured that the files I provided here on BHW are 100% safe and clean to use on (production or testing) WordPress websites.

How do I not make the same mistake again? I know, I know, don't download random shit. But other than that, is there something better than VirusTotal?

It's important to verify the source and not download from any 'free' GPL websites.
While we feel very sorry for you and it feels like you got trapped by a 3rd free party website that included some backdoors in your website, I wanted to make sure you're using the right sources from now on.
Please let us know what files you need and I am happy to provide you with all the safe files (including the receipts of the original payments) in this topic.

And to offer you a plaster on the wound, I'm happy to provide you a lifetime VIP access account for free on our GPL market website.
Again, we are really sorry that you had such a bad experience with the GPL services. Take care bro and please reset your passwords everywhere.
 
Are you sure this was from downloading WordPress themes/plugins? Also which Google sites have you downloaded them from? It seems like your entire cookies with all information have been stolen for which I recommend you change anything that you still have and reset your entire PC/phone. Also always use 2fa and don't disable Windows anti-virus as it helps a lot. Anything that i use has 2fa set up that is on a phone that i use only for 2fa on it;s own data so even if someone tries going to my main google accounts,discord/telegram/payment stuff when i'm hacked they won't be able to get anything.
 
How they will be able to acces all those info from a plugin that you installed on your wordpress?
That can't happen
Why no one talked about that in the above comments
The plugin can only affect your website or if the login info of those social media accounts are linked to that website via wise another plugin
 
How they will be able to acces all those info from a plugin that you installed on your wordpress?
That can't happen
Why no one talked about that in the above comments
The plugin can only affect your website or if the login info of those social media accounts are linked to that website via wise another plugin
By extracting the zip
 
And to offer you a plaster on the wound, I'm happy to provide you a lifetime VIP access account for free on our GPL market website.
Again, we are really sorry that you had such a bad experience with the GPL services. Take care bro and please reset your passwords everywhere.
damn maybe i should get hacked more often too :poop: :p, But i don't because i use Festingers exclusively :cool:

Disclaimer: I don't work for festinger, Im just madly in love with his giant GPeenL. Just look at that sexy customer service for real.

On that note, seriously don't download things from google. If a site doesnt offer a price tag it's probably trash. And if it does, consider it trash anyway until you read other people talk about it.
 
I had this issue once, and I think it was caused by some seller who had given me a website for a review copy, and he had some plugin or theme that was nulled, and all of my sites from that server were hacked and had a redirection setup. I was able to get out of the problem, and I learned the lesson never to use any nulled themes and also only use minimal plugins and delete the ones that you don't want.
 
don't want to be that guy but have you confirmed that nulled themes was the attack vector?
has a local malware scanner picked up anything relevant? first thing you should be doing is making sure your computer is not still compromised.

virustotal definitions are decent imo. good to run a local A/V (eset or kaspersky). sandboxing all downloads is a little overkill and overwhelming for checking nulled themes.

best defense is being aware.
#1 rule is don't do anything pirate on the same computer you do finances on.
#2 like @sscaz said, use MFA. this would have stopped the bank hacker.
#3 use a local a/v and/or firewall with decent and updated definitions.
 
This is why I made up my mind to get divi lifetime account so that the issue of theme will come to an end
 
Tomorrow, you'll find out they're stealing your house and car because of these nulled WP Plugins :suspicious:

Sorry for your loss dude, but there's no way they hacked your gmail, credit card & other accounts if the login data is not stored in your website,
You should have downloaded a zip file and reuploaded again to your website,

Ofc, technically it's possible if you extracted the zip and it contains some hidden virus somewhere,
But usually, you'll need to run some sort of exe file to get the virus running,
Even tho it's possible to get things done without even running it as well, but these are way advanced & harder to implement,
It doesn't make a sense for any kind of hackers to implement these files in a nulled WordPress themes/plugins,

You got your stuff hacked some other way for sure,
Take your time and dig for whatever you have installed in your phone/computer in the last period & you might have a better idea,

You have to format both of your computer and other devices just in case,
Implement other security measures to make sure that won't happen again, they might be annoying sometimes, but they're necessary,
Better be safe than sorry!
 
wow I never knew this was happening.

I've been with Deleted member 752298 for a few years and had no problems whatsover.....
It's not their fault, it probably came from one of the sites i found on google

hmmm indeed. Posted this 5 yrs back lol.

https://www.blackhatworld.com/seo/poc-why-vt-scans-shouldnt-ever-be-trusted-for-detecting-malicious-web-scripts.1055564/
Check it out op. Don’t trust any kind of scanners. Do the code review yourself, if you can.

Damn really, then I should learn to review the code myself

There is a need to investigate this. Deleted member 752298 downloads original files from the publishers... It must have been a mistake from another file!
Yes, must've been from another file, I'm not accusing Festinger, I just mentioned where I downloaded the themes from
 
Last edited:
i use some nulled plugins, but i go through most of the code myself for such things with the random created links on a website years ago.
im more willing to waste time on sifting through code than spend an extra $500-$1000 for plugins per website
 
Back
Top