Urgent Security Issue: Suspicious Files Created in Moview Template Directories - Forum | JoomShaper
Staff replied Templates

Urgent Security Issue: Suspicious Files Created in Moview Template Directories

Asked by Kostas Konstantinidis 1 month ago Last activity 1 month ago

Hello, our file-integrity monitor detected the following suspicious files.
All four files contain PHP code that only prints the text: Nxploited-Create
The forum security filter prevents me from posting the exact PHP line.
GRMDB Sentinel Alert
Time: 2026-08-26 22:05:03
Root path: /usr/www/users/grmdba
Files scanned: 22367
New: 4
Modified: 0
Deleted: 0

NEW FILES:

  • templates/shaper_moview/layout/nxtest.json
  • templates/shaper_moview/layout/nxproof.php.json
  • templates/shaper_moview/nxproof.php.json
  • templates/nxproof.php.json

This appears to be a test confirming that files can be created remotely inside the template directories. Could this be related to a known vulnerability in the Moview template, Helix framework, or SP Page Builder? Please forward this information to your security/development team and let us know what action or update is required. We have preserved evidence and will now remove the files.

Thank you /kostas

1 reply

Paul Frankowski Senior Staff
1 month ago · edited

Thanks, I guess this is your 2nd, duplicate topic about the same.

Yes, delete those files. And remember to use my .htaccess inside templates/shaper_moview/layout/ folder (!) you can also use inside /images .

Log in to reply.