I’ve purchased a WordPress theme. The theme is full of bugs, i’ve contacted the developer and gave him access to the backend of my wp with administrator rules and now i get only suspicious activity from them. This looks like a lawsuit. Please restrict their activity and don’t let hackers sell their stuff here, here are the logs on my server after i gave them access to the backend:

 lfd on Suspicious process running under user

Time:    Thu Jun  8 08:12:43 2023 +0300
PID:     984436 (Parent PID:940074)
Account: seavieweforie
Uptime:  75 seconds



Command Line (often faked in exploits):


Network connections by the process (if any):

tcp: [redacted ip]:39798 -> [redacted ip]:443

Files open by the process (if any):


Memory maps by the process (if any):

I don’t see anything inherently suspicious in those logs. It could just be a hanging/zombie process due to some technical issue.

The two IP addresses under the network connections are identical and I believe them to be your own server’s IP, so I’ve redacted them.

The heap looks fine. I removed a bunch of standard shared libraries from the output as they’re not relevant but don’t see anything suspicious. The “files open by the process” also looks fine, nothing unusual there for an lsphp process.

Edit: Upon further review of the cPanel CSF/LFD configuration, I don’t see any significant details in your logs that indicate a problem. The alert in question is generally broad and does not directly indicate a security issue. In fact, it seems easy for a developer to trigger this alert while working.

My new suggestion is to send the alert to the author and ask if they know what might have triggered it.


Looks like the PHP itself creating/updating the logs.
Apart from that, as you agreed to share the access, it’s hard to talk about anything illegal, it’s volunteer.

The logs will be unrelated. The process is lsphp which is a LightSpeed instance. As such, it will naturally update the logs, access the passwd file for permission management, and such. More likely is that the developer deleted a file while it was still running, or something similar, since their PHP files seem to be streaming over the network.

