I’m looking for an experienced Linux incident response / sysadmin to help with a server issue.
A Linux server previously had an xmrig miner infection. Most artefacts have been removed, but something on the system is still intermittently attempting to download a miner script via wget.
The application code has been thoroughly checked and appears clean. This looks like a system-level persistence issue (cron, systemd service/timer, user-level service, SSH abuse, etc.).
What I’m looking for: • Identify and remove the persistence mechanism • Confirm whether there is any evidence of data access/exfiltration • Advise whether the server is safe to keep or if a rebuild is recommended
Context: • Ubuntu server • Node.js / Next.js app • PM2 • auditd already enabled • Sensitive app secrets will be rotated after the work
Credentials WILL be checked prior to work commencing
Low-Poly Hard-Surface Asset Pack Category: 3D Animation, 3D Design, 3D Graphic Design, 3D Modelling, 3D Rendering, 3D Visualization, 3ds Max, Blender, Concept Art, Game Development Budget: $30 - $250 AUD
15-Apr-2026 10:03 GMT
HVAC Startup Needs Logo Design Category: Branding, Creative Design, Graphic Design, Logo Design, Visual Design Budget: $30 - $250 AUD
Google Ads Grant Charity Setup Category: Advertising, Digital Marketing, Google Ads, Google Adwords, Google Analytics, Internet Marketing, Search Engine Marketing (SEM), SEO Budget: £20 - £250 GBP
15-Apr-2026 09:56 GMT
Modern Logo Rebranding Design Category: Adobe Illustrator, Branding, Creative Design, Graphic Design, Illustration, Logo Design, Print Design, Typography, Visual Design Budget: $30 - $250 USD