Urgent Security Issue: Suspicious Files Created In Moview Template Directories - Question | JoomShaper

Urgent Security Issue: Suspicious Files Created In Moview Template Directories

Kostas Konstantinidis

Kostas Konstantinidis

Template 3 days ago

Hello, our file-integrity monitor detected the following suspicious files. All four files contain PHP code that only prints the text: Nxploited-Create The forum security filter prevents me from posting the exact PHP line. GRMDB Sentinel Alert Time: 2026-08-26 22:05:03 Root path: /usr/www/users/grmdba Files scanned: 22367 New: 4 Modified: 0 Deleted: 0

NEW FILES:

  • templates/shaper_moview/layout/nxtest.json
  • templates/shaper_moview/layout/nxproof.php.json
  • templates/shaper_moview/nxproof.php.json
  • templates/nxproof.php.json

This appears to be a test confirming that files can be created remotely inside the template directories. Could this be related to a known vulnerability in the Moview template, Helix framework, or SP Page Builder? Please forward this information to your security/development team and let us know what action or update is required. We have preserved evidence and will now remove the files.

Thank you /kostas

0
1 Answers
Paul Frankowski
Paul Frankowski
Accepted Answer
Senior Staff 3 days ago #232577

Thanks, I guess this is your 2nd, duplicate topic about the same.

Yes, delete those files. And remember to use my .htaccess inside templates/shaper_moview/layout/ folder (!) you can also use inside /images .

0