Hello, our file-integrity monitor detected the following suspicious files.
All four files contain PHP code that only prints the text: Nxploited-Create
The forum security filter prevents me from posting the exact PHP line.
GRMDB Sentinel Alert
Time: 2026-08-26 22:05:03
Root path: /usr/www/users/grmdba
Files scanned: 22367
New: 4
Modified: 0
Deleted: 0
NEW FILES:
- templates/shaper_moview/layout/nxtest.json
- templates/shaper_moview/layout/nxproof.php.json
- templates/shaper_moview/nxproof.php.json
- templates/nxproof.php.json
This appears to be a test confirming that files can be created remotely inside the template directories. Could this be related to a known vulnerability in the Moview template, Helix framework, or SP Page Builder? Please forward this information to your security/development team and let us know what action or update is required. We have preserved evidence and will now remove the files.
Thank you /kostas