Following my previous message, the access log shows that the suspicious files were created through repeated POST requests to:
/index.php?option=com_ajax&plugin=helix3&format=json
The requests came from IP 169.58.30.114 on 26 August 2026 at 18:55–18:58. Immediately afterwards, the same IP successfully accessed the newly created nxproof files.
The site runs Joomla 6.1.3 and JCE 2.9.99.10. Please forward this to your security team and let us know whether a Helix3 patch or temporary protection is available.
Thank you.