Hi,
Thanks for the follow-up.
The injected snippet is not part of either the Helix Ultimate or SP Page Builder update. We have not identified any such code in our released packages.
If the same injected code is present on multiple websites, it is more likely that they were compromised through another attack vector (for example, outdated extensions, compromised administrator credentials, or the previous security incident) before or during the update. Maybe the update itself simply made the already injected code visible.
We recommend the following:
- Perform a full malware scan on each affected website.
- Check for any unauthorized Super User accounts.
- Update Joomla and all third-party extensions to their latest versions.
- Change all administrator, hosting, FTP, and database passwords.
- Install a reputable firewall/security extension to help detect and prevent future attacks.
If you continue to find the same injected code after completely cleaning a site, please provide temporary Joomla administrator access and FTP access. We'll be happy to investigate further to determine whether the code is still being injected and, if so, from where.
Best regards,