Droplet Malware Cleanup and Restore

Job ID: 40320717

Budget: $30 – $250 USD

My DigitalOcean droplet hosts several WordPress sites and was suspended after a flood of spam. Scans show clear signs of malicious code injection across at least one installation, and the droplet itself now refuses to boot normally.

What I need you to do
• Bring the droplet back online safely, removing every trace of injected code and any server-level leftovers that could relaunch the attack.
• Clean each WordPress instance in place—there are no usable backups—then reinstall fresh core files and replace any plugins or themes that prove irreparable. I’m not sure which extensions were hit, so you’ll determine what stays, what gets re-installed and what must be deleted.
• Re-upload the cleaned sites, verify front-end and admin access, and ensure outgoing mail is no longer flagged as spam.

Acceptance criteria
1. Droplet starts normally with no malware alerts from tools such as Wordfence or ClamAV.
2. All WordPress dashboards load, page speed is reasonable, and no hidden redirects or spam links remain.
3. Mail-test reports a clean score and the droplet’s IP is clear from major blacklists.
4. A brief hardening report lists actions taken plus next-step recommendations (firewall, backups, updates).

Tool familiarity with SSH, WP-CLI, malware scanners, and DigitalOcean console will be invaluable. Let me know your turnaround time and any questions you have before starting.