Issue With The SP Page Builder 6.6.2 Update - Question | JoomShaper

Issue With The SP Page Builder 6.6.2 Update

O

OPAWEB

SP Page Builder 1 month ago

I’ve just realized that many of my clients' sites are infected. I have already updated Joomla to version 5.4.7 and all other components—including SP Page Builder—to version 6.6.2. The site loads correctly, but the console shows various requests; I haven't been able to identify where they are being called from. I need to know exactly where to look or what steps to take to stop these console errors from appearing. I can't upload photos, but they're like...

"Refused to apply style from 'https://misite/images/6pu9vaqq/style.css?143fb2b8f5d98f82feb246ecc61db33d' because its MIME type ('text/html') is not a supported stylesheet MIME type, and strict MIME checking is enabled."

0
11 Answers
Paul Frankowski
Paul Frankowski
Accepted Answer
Senior Staff 1 month ago #228112

Hi,

we have whole topic for webmasters like you >> https://www.joomshaper.com/forum/question/45152

Just read & scroll, and you will find all the answers, and tools. There's a lot of knowledge, tips and stories from other users there.

0
Paul Frankowski
Paul Frankowski
Accepted Answer
Senior Staff 1 month ago #228116

I’ve just realized that many of my clients' sites are infected.

If all websites were/are on the same server, that means your hosting provider is at fault. You should have your websites separated. That way, one infected site won't harm the others or allow access to other sites.

Please contact with your hosting support in that topic (!) Otherwise one fixed/secured site still be infected after just hour(s).

0
O
OPAWEB
Accepted Answer
1 month ago #228124

Cada sitio tiene su propio servidor. Pero esta vulneravilidad ha generado problemas en muchos de ellos. Donde debería ejecutar esta herramienta? solicito apoyo ya que no sé como se descarga o como se debe implementar.

0
Paul Frankowski
Paul Frankowski
Accepted Answer
Senior Staff 1 month ago #228131
  1. Ask your hosting support to scan your sites using their tools, and remove all malware files they will find. This is the first level—it's essential.
  2. Then you can use https://github.com/zkrana/joomla-security-scanner/ (our tool)
  3. Or use RsFirewall to scan, then use FTP or FileManager from cPanel to delete all malware files
0
O
OPAWEB
Accepted Answer
1 month ago #228136

I’ve already done everything requested. RsFirewall is flagging most of the site's files as suspicious, but when I try to locate them via FTP, they don't appear. Something in the console is trying to call them, but I don't know how to find it. That’s where I need your help, because I know I’m not the only one facing this problem.

0
Rob
Rob
Accepted Answer
2 weeks ago #231872

Hi paul, I also have a website that hase been hacked, it was a pretty big job to clean up the mess, indeed. I also cleaned the database by search. That scanner of the git was able to clean up the leftovers for me. After that he index was still full of references to 3838 wrong css files. Then I deleted all brochures of the same name via FTP and pagebuilder and helixultimate installed [newly. Finally many incorrect references were gone. Notice the hacker had the possibility of installing a plugin with the name jp9e6ae8 that could actually retrieve all data from the website like DB passwords, names etc. so also the database and admin password should be changed really it cost me two long nights. (reinstalling would have been faster for this mini onepage website now it's almost done. There was also a super user made with the same name jp9e6ae8

Only after installing helix ultimate can I set the template such as logo and menu settings. Joomla also reports that everything has been layered up, but I don't see that on the front. the website shows a standard helixultimate. via the F12 inspector button I see the following message about mime types. Now I can't save it properly. ;-(

It seems to look for : media/com_sppagebuilder/assets/iconfont/icofont/icofont.min.css This is not a default media pagebuilder directory. And restore it is not an option. media/com_sppagebuilder/ normaly haves /css and /placeholder within it.

Trying to save te template settings gives:

Refused to apply style from 'MY-WebSITE/media/com_sppagebuilder/assets/iconfont/icofont/icofont.min.css?fba6c85d81d0c68346fb69189fc1e35e' because its MIME type ('text/html') is not a supported stylesheet MIME type, and strict MIME checking is enabled.

I want to buy a : "I hate hackers" T-shirt

After cleaning the website and reinstall Joomla 5.4.7 core. backup the page, delete pagebuilder and helixultimate. clean the folders, so it is absolute new. reinstall helix ultimate and pagebuilder. It is not working like it did. I have malware scanfiles that makes me assume that the hole hack started in the icofontfolder that should not exist.

Anyway: the absoluut solution is not found.

PS: I would like to remind you and your colleagues that the hacker gained access through a vulnerability in JoomShaper software. We, the users of the software, are not to blame for the fact that the software we implicitly trusted was not secure enough. It would be appropriate to set up a support channel to assist those affected and provide a description of the process for resolving the issue. I find the answers I am seeing right now very inadequate and evasive. "Just check this link, and bye!". I don't think that is professional.

0
Paul Frankowski
Paul Frankowski
Accepted Answer
Senior Staff 2 weeks ago #231875

Hi Rob,

read my guide: https://www.joomshaper.com/documentation/sp-page-builder/troubleshooting#how-to-clean-an-infected-joomla-4x-6x-site

it will help you clean those werid files. yes, all of them must be deleted with folders.


about t-shirt, sorry to say it, but it will not help. We can talk more about it on Joomla Day 2026 Germany.

0
Rob
Rob
Accepted Answer
2 weeks ago #231876

it is not enuf dear Paul, just sending a link is not enuf for an security issue that started by unsave Joomshaper software.

I lake to shake hands in germany.

0
Paul Frankowski
Paul Frankowski
Accepted Answer
Senior Staff 2 weeks ago #231879

I can help clean your site using our extension, but share access in Hidden Content area

0
Rob
Rob
Accepted Answer
2 weeks ago #231877

PS when is the Joomla day in Amsterdam? Amsterdam Berlin is 8 houers driving

0
Paul Frankowski
Paul Frankowski
Accepted Answer
Senior Staff 2 weeks ago #231878

This year edition is in DE, where be next we will know after. I hope it will be there too.

0