Malware attack campaign has already compromised more than 100,000 websites worldwide. Google blacklisted over 11,000 domains because they were used to serve malware that has been brought by SoakSoak.ru. The malware is also able to download further malicious payloads on the compromised machine. Malware operates by modifying a file located at wp-includes/template-loaderphp which causes. a malicious. file to be loaded on every page visited on the website and this swobject.js file includes a malicious java encoded script malware.”]
Source: http://securityaffairs.co/wordpress/31132/cyber-crime/soaksoak-malware-100k-wordpress-sites.html