Pharma Hack and SEO Spam Injection: When Google Sees a Different Site Than You Do
Pharma Hack and SEO Spam Injection: When Google Sees a Different Site Than You Do

Someone tells you your site is showing up in search results for prescription drugs. You load the page. It is completely normal. You load it again in a private window. Still normal. It is tempting to conclude the report was wrong.
It was not. This class of attack works precisely by showing you the clean version.
Cloaking, in one paragraph
The injected code inspects each request before deciding what to return. If the request looks like Googlebot, or carries a referrer from a search engine, it serves spam. If it looks like the site owner loading the page directly, it serves the real content. The result is that the infection is invisible in exactly the circumstances where you would look for it, and plainly visible to the search engine whose opinion determines your traffic.
The payload is usually pharmacy, gambling or counterfeit goods, hence the informal name. The mechanism is the same regardless of what is being sold.
How to confirm it
Do not trust the browser. Loading the page normally is the one test guaranteed to return a false negative.
Use a site: search. Search your domain with the site: operator and read the titles and snippets. Cloaked spam shows up here because this is Google's copy, not yours.
Use URL Inspection in Search Console. Inspect an affected URL and look at the rendered content Google actually received. A mismatch between that and what your browser shows is the whole diagnosis.
Check Search Console's Security Issues report. Google often labels this directly.
The full detection pass is in how to check if your website has been hacked.
Where the injection usually lives
Cloaked spam has to run on every request, so it sits somewhere that always executes. In practice that means a small number of places.
The database. Injected into post content, options or widget tables, which is why a clean reinstall of your files does not always remove it.
Theme and plugin files. Often a single obfuscated block appended to a legitimate file, so a casual look at the directory shows nothing unusual.
.htaccess or server configuration. Conditional rules that redirect or rewrite based on user agent or referrer.
A separate loader. A small file whose only job is to pull the real payload from elsewhere, so the visible code changes whenever the attacker wants.
Because the payload can live in the database as readily as in a file, restoring a file backup is frequently not enough. The cleanup sequence that does cover both is in how to remove malware from your website.
Why this one costs more than it looks
A defacement is embarrassing and obvious, so it gets fixed the same day. Cloaked spam is neither, and it often runs for months before anyone notices. By then your domain has been associated with spam content across a large number of indexed URLs.
That is a search problem as much as a security one, and cleaning the code does not reverse it on its own. See website security vs SEO for what the damage actually consists of, and recovering rankings after a hack for the work that follows the cleanup.
If Google has flagged the domain, the warning clears only after a successful review: is your website blacklisted by Google?
Not sure this is what you have? Start at the triage guide.
Put this into action with eSEOspace
We help businesses grow with website development that actually performs. Explore the services behind this guide:
Get a FREE Audit
We'll perform a comprehensive SEO, AEO, GEO & CRO audit of your website — completely free — and show you exactly how to outrank your competitors.
Don't have a site yet? Get in touch →
Get a FREE GEO/AEO/SEO Audit
We'll analyze your site's SEO, GEO, AEO & CRO — completely free — and show you exactly how to get found across Google and AI answers.
Don't have a site yet? Get in touch →
Great — your audit is on the way!
We'll send your free SEO/GEO/AEO/CRO audit within the next few hours. Where should we send it?
You're all set! ✓
Your free audit is being prepared — check your inbox in the next few hours. Talk soon!






