Hi,
An year ago I had a conflict with an author on this subject.
My advice is to communicate this with the proof of the Envato. This malware is very well hidden in PNG and it is very difficult to detect by Envato team. They probably thinking that’s an image.
In my opinion I think : The author stole a template from torrents and change it . From my experience on some bizarre websites, I discovered malware hidden in png or svg files. For this reason it is best to buy a template.
I hope to resolve this issue.
Regards,
Yes that is why I purchased a theme thinking was safe.
It is not excuse for them to not find this one because social.png is never a file needed in any theme and well known Malware file. Here is a screen shot of it in their download zipped file.
Yes this malware very well done and hard to detect. Envato had no way to detect it. These types of malware do not cause damage on your site but they change your meta tags and page title with advertisings and affects your website in search engine . My advice is to open that file with notepad, sublimetext or other IDE and send those at Envato. Also may be that malware is in the other files and that social.png be called somehow in code.
I’m sorry for what happened to you.
"thezoc"
I am concerned with your lack of understanding of how serious social.png is. You have no idea how bad it is until your IP has been blacklisted for sending out thousands of emails or spam posts at which point your web hosting provider shuts down your or your clients website causing them to be out of business.
Not a easy thing to find??? this one also worries me because social.png is the number one file you should search your cPanel or what ever you are using for constantly these days. It is the new STI of the web world.
Seriously read this article soon please: http://stackoverflow.com/questions/24967628/what-is-the-purpose-of-strange-false-social-png-in-many-wordpress-themes
I think it’s fair to put here author and theme name because others have this problem to alert.
It’s too bad that made this author. I checked on google and these types of malware hidden in image files can send information from your database and not be detected if you use a shared hosting package.
It would be insane to put a file in a theme that is internationally known as the worst malware file name on the market. Why would anyone use the name social.png for a legitimate file knowing that all malware software and anyone doing their due diligence, would immediately delete it?
All PNG files have code embedded in them so for me it is hard to tell. I simply do not wish to take the chance when the odds are 90+% that this is malware.
You have a look at this code and see if you can read where and if there is an injected malicious action here. LOL
I wasn’t aware of a malware with social.png name and I can’t be the only one, social.png can easily be the name of the social icons for the theme… but most themes will / should be using icon fonts anyway.
That doesn’t look dodgy to me but run it through a php obfuscator such as http://fopo.com.ar/
It doesn’t have the obvious php code such as variables ($something = ) and php start / end tags.
I think it’s just a poorly named file rather than malware… let Envato know about the social.png malware and they can check themes for the issue, but it’s unlikely any theme from Themeforest will have it imho.
The social.png exploit is about 45kb in size. The file in your screenshot is 5kb in size.
This is just a picture! A legitimate picture. There is no hidden code here.
Please update your support ticket (and anywhere else you have posted this) to say there is nothing to worry about.
I have files called social in my items too. There are hundreds of exploits and they are named all sorts of things. Even functions.php can contain exploits, and that file is required for WordPress to work. Thinking something is an exploit based on file name alone is not the right way to do things.
Double click on that picture and open in it, what do you see? (And no, a php script named .png will not run a virus on your computer when opened. It actually won’t run at all even if you uploaded it to a website, this script needs to be triggered a special way)
Firstly - Google social.png -what do you find? thousands of articles about the malware famously known as social.png. Nothing else, no reference to real file with that name…it is in fact the most highly exploited malware file name this year. Why use it at all???
Secondly, I will repeat…this is just really bad planning to use an exploited file name… I delete it on site - no questions asked!. The functions.php yes I understand the need to review that file because it is in fact properly named, is required by all WordPress websites and is a php file. In addition the symptom is it breaks your theme when this happens with an easy fix usually to remove the line of code. That one you see the results immediately and no one can live without it in the WP world without a lot of effort to change a lot of references to it.
Anyways, not happy to receive a file called social.png from anyone. Sorry but that’s from experience!
but if you read my post, even I didn’t know the exploit disguised as a png file, the author is probably the same, 99% it was done by accident and they weren’t aware, if you let them know they can rename it in future so not to raise suspicions.
First time I had heard of that exploit too. Although that “type” of exploit is really popular, it can be called anything, even “untitled.bmp” if you wanted to.