Nulled WordPress Themes Ruined Me

First of all, I am really sorry to read that you had a bad experience using a bunch of nulled WordPress themes and that you lost important access to your social media accounts.
I feel the pain bro. Using nulled themes and plugins from foreign sources can be a huge risk for your WordPress website.

We have been in the GPL market since 2018 and I have been developing WordPress websites for over 15 years now.
As this topic has been forwarded by several of our customers (half of BHW is using our services) I felt it was the right choice to leave a personal reply here.

Since we have been providing/sharing many WordPress clean and original WordPress themes and plugins here on BHW, and on our own website repository, it's impossible that we're part of this scam.
As other members suggested, the VirusTotal Report is very limited. However, you can rest assured that the files I provided here on BHW are 100% safe and clean to use on (production or testing) WordPress websites.



It's important to verify the source and not download from any 'free' GPL websites.
While we feel very sorry for you and it feels like you got trapped by a 3rd free party website that included some backdoors in your website, I wanted to make sure you're using the right sources from now on.
Please let us know what files you need and I am happy to provide you with all the safe files (including the receipts of the original payments) in this topic.

And to offer you a plaster on the wound, I'm happy to provide you a lifetime VIP access account for free on our GPL market website.
Again, we are really sorry that you had such a bad experience with the GPL services. Take care bro and please reset your passwords everywhere.

Thanks for the lengthy reply, much appreciated. I'm NOT saying this is your guys fault, I just mentioned where I got the themes from, and I see that some people assume that it could've been from your site. And I'm sure that it wasn't from your site, because I've used your site before and never had problems. Again thanks for the advice!

Are you sure this was from downloading WordPress themes/plugins? Also which Google sites have you downloaded them from? It seems like your entire cookies with all information have been stolen for which I recommend you change anything that you still have and reset your entire PC/phone. Also always use 2fa and don't disable Windows anti-virus as it helps a lot. Anything that i use has 2fa set up that is on a phone that i use only for 2fa on it;s own data so even if someone tries going to my main google accounts,discord/telegram/payment stuff when i'm hacked they won't be able to get anything.
Yes, I've enabled 2fa on everything
 
Thanks for the lengthy reply, much appreciated. I'm NOT saying this is your guys fault, I just mentioned where I got the themes from, and I see that some people assume that it could've been from your site. And I'm sure that it wasn't from your site, because I've used your site before and never had problems. Again thanks for the advice!
Please use multi quote instead of posting multiple replies,
That would make the thread kinda spammy
 
How they will be able to acces all those info from a plugin that you installed on your wordpress?
That can't happen
Why no one talked about that in the above comments
The plugin can only affect your website or if the login info of those social media accounts are linked to that website via wise another plugin
Well, everything is in zip files, maybe it got in when I unzipped them?

By extracting the zip
haha just replied this on the comment above

damn maybe i should get hacked more often too :poop: :p, But i don't because i use Festingers exclusively :cool:

I don't feel like accepting the offer because it's not their fault and he's too nice.... my fault that I mentioned Festinger

Tomorrow, you'll find out they're stealing your house and car because of these nulled WP Plugins :suspicious:

Sorry for your loss dude, but there's no way they hacked your gmail, credit card & other accounts if the login data is not stored in your website,
You should have downloaded a zip file and reuploaded again to your website,

Ofc, technically it's possible if you extracted the zip and it contains some hidden virus somewhere,
But usually, you'll need to run some sort of exe file to get the virus running,
Even tho it's possible to get things done without even running it as well, but these are way advanced & harder to implement,
It doesn't make a sense for any kind of hackers to implement these files in a nulled WordPress themes/plugins,

You got your stuff hacked some other way for sure,
Take your time and dig for whatever you have installed in your phone/computer in the last period & you might have a better idea,

You have to format both of your computer and other devices just in case,
Implement other security measures to make sure that won't happen again, they might be annoying sometimes, but they're necessary,
Better be safe than sorry!

I did unzip the zip files, and no I don't download any other pirated/nulled software on my PC, just WP related stuff
 
Tomorrow, you'll find out they're stealing your house and car because of these nulled WP Plugins :suspicious:

Sorry for your loss dude, but there's no way they hacked your gmail, credit card & other accounts if the login data is not stored in your website,
You should have downloaded a zip file and reuploaded again to your website,

Ofc, technically it's possible if you extracted the zip and it contains some hidden virus somewhere,
But usually, you'll need to run some sort of exe file to get the virus running,
Even tho it's possible to get things done without even running it as well, but these are way advanced & harder to implement,
It doesn't make a sense for any kind of hackers to implement these files in a nulled WordPress themes/plugins,

You got your stuff hacked some other way for sure,
Take your time and dig for whatever you have installed in your phone/computer in the last period & you might have a better idea,

You have to format both of your computer and other devices just in case,
Implement other security measures to make sure that won't happen again, they might be annoying sometimes, but they're necessary,
Better be safe than sorry!

@hideath was right

Check for malware in system use malware removal tools

If you have used same passwords on websites login and social then its possible

Find the exact source of the theme from where you got by googling and check reddit for website review or similar issues posted by user
 
How did they manage to hack into your social media using your wordpress website? That is what I really want to know. Same password?
 
First of all, I am really sorry to read that you had a bad experience using a bunch of nulled WordPress themes and that you lost important access to your social media accounts.
I feel the pain bro. Using nulled themes and plugins from foreign sources can be a huge risk for your WordPress website.

We have been in the GPL market since 2018 and I have been developing WordPress websites for over 15 years now.
As this topic has been forwarded by several of our customers (half of BHW is using our services) I felt it was the right choice to leave a personal reply here.

Since we have been providing/sharing many WordPress clean and original WordPress themes and plugins here on BHW, and on our own website repository, it's impossible that we're part of this scam.
As other members suggested, the VirusTotal Report is very limited. However, you can rest assured that the files I provided here on BHW are 100% safe and clean to use on (production or testing) WordPress websites.



It's important to verify the source and not download from any 'free' GPL websites.
While we feel very sorry for you and it feels like you got trapped by a 3rd free party website that included some backdoors in your website, I wanted to make sure you're using the right sources from now on.
Please let us know what files you need and I am happy to provide you with all the safe files (including the receipts of the original payments) in this topic.

And to offer you a plaster on the wound, I'm happy to provide you a lifetime VIP access account for free on our GPL market website.
Again, we are really sorry that you had such a bad experience with the GPL services. Take care bro and please reset your passwords everywhere.
Hello buddy!,
Can i have the lifetime VIP access account for free on your GPL market website please.
I'll appreciate it!!
 
I had the same issue with a nulled plugin that I installed to my website and website had a red flag in search engines and twitter(x)
 
90% of nulled plugins and themes on the web have a backdoor, because that's the easiest and securest way to make money from malware installs, and that's a huge business with dozens of affiliate programs on Draknet. Only a suicider will upload the nulled shit to his own server.

Here you go: https://en.wikipedia.org/wiki/Darwin_Awards

P.S. If someone thinks that some magic voodoo antivirus tools can protect a WordPress site against backdoors injected directly into the PHP code, he will be deadly surprised ;)

A small list to start with: https://github.com/backdoorhub/shell-backdoor-list
 
Last edited:
First RULE to build a website = NEVER use Nulled themes or plugins.
If you cannot pay for a theme or a plugin find a job and do something else with your life.
 
This is wrong, its impossible for nulled themes to access your personal data like bank accounts, gmails and such!

What happend is you downloaded a stealer, not a nulled theme. Clicked on the wrong download link in some public download websites.

First: use ublock origin on your browser. It will remove all ads, and this download link is an ad.

Second: Buy kaspersky for cheap. it will cost you $11 for a whole year. totally worth it.

Third: Only use websites which you can download the nulled theme directly from. Not through some download service.

Fourth: Specialized forums are the best, as wiser members will always catch the viruses. Or reputable gpl services which charge you money as they have reputation to keep.

First and Second will protect you from getting your pc hacked.

Third and Fourth will protect your server.

Finally, a sure way to check code authenticity even if you can't code, is to download same version from two different sources, and compare the files using Windows Merger.

If there is a different then you know which websites is infecting websites and who provides clean code.

A step further, is generating footprint for malicious code and get access to all the websites this culprit has been infecting over the years .. then, monetize! I really think I should stop here.
 
Last edited:
I also did the same in 2017
My 38 websites were hosted in a single cPanel. I downloaded a premium theme for free. Then my all sites in the cPanel were affected.
 
Back
Top