Posted Nov 28, 2012 12:37 UTC (Wed) by njwhite (subscriber, #51848)
Parent article: Backdoor inserted into Piwik
Their advice to backup config.ini.php and then unpack a fresh install is sensible, but does point to an issue with having a config file be direct code; if they'd decided to add part of the backdoor to config.ini.php, restoring things could have got rather trickier.
Anyway, it's a good advisory, and it looks like they did a very good job of responding. The forum post linked to there has more details of what the backdoor does, for those interested: http://forum.piwik.org/read.php?2,97666