Subject: Security Incident Report - Malicious code injection in Helix Ultimate template files
Dear JoomShaper Support Team,
I am writing to report a security incident that affected my Joomla website and involved files belonging to the Helix Ultimate template framework. I want to bring this to your attention so you can verify whether this issue may affect other users of your products.
What happened:
Our security monitoring plugin (AdminTools) detected unauthorized modifications to the following files:
• templates/shaper_helixultimate/index.php
• templates/shaper_helixultimate/js/main.js
Both files had malicious obfuscated JavaScript code injected immediately after the <head> tag (in index.php) and within the main JS file. The injected code (identified by the id='jmtouch') established a connection to an external server and redirected website visitors to a malicious spam site (followfromapps.icu).
The same payload was also injected into the Cassiopeia default template file (templates/cassiopeia/index.php), confirming this was a coordinated, automated attack targeting multiple template files simultaneously.
Timeline:
• Day 1: Malicious code detected and manually removed from index.php files
• Day 2: Site was reinfected automatically — same files, same payload
• Investigation revealed main.js as the persistence mechanism enabling reinfection
• All files have now been restored and passwords changed
What we would ask you to verify:
We kindly ask you to check whether:
- Any of your official Helix Ultimate distribution packages may have been compromised
- There is a known vulnerability in Helix Ultimate that could be exploited for this type of injection
- Other users have reported similar incidents
We are happy to provide additional technical details or samples of the malicious code if helpful for your investigation.
Thank you for your attention to this matter.
Best regards
Joomla 6.1.1
SPpageBuilder 6.6.2
Helix Ultimate 2.2.6