Crypto-Powered WordPress Malware Refuses to Die
8 Articles
8 Articles
🚨 SC malware, which uses Ethereum infrastructure, poses a persistent threat to WordPress sites. 🧩 Sucuri announced that the malicious payload is present in at least eight different locations simultaneously. 🔐 Attackers can hijack administrator sessions and maintain access through $ETH-linked RPC gateways. 🛒 The malware poses a data collection risk by adding JavaScript to the payment step on e-commerce sites. Read More: WordPress malware usin…
Crypto-Powered WordPress Malware Refuses to Die
A highly persistent WordPress malware strain is using Ethereum infrastructure to stay alive, with redundant copies scattered across compromised sites allowing it to rebuild itself even after attempted cleanup.
WordPress Backdoor Rebuilds Itself After Cleanup Using Files, Database, and Shared Memory
Ravie LakshmananOct 01, 2026Vulnerability / Web Security Cybersecurity researchers have shed light on a WordPress compromise in which threat actors deployed multiple persistence mechanisms to ensure that the final payload kept returning without having to infect the site again. The backdoor has been codenamed SC after the "SC_" markers present in the injected content. Sucuri
WordPress Malware Comes Back After Removal Using a Self-Healing Backdoor
A WordPress backdoor is bringing deleted malware back within seconds, turning routine cleanup into a cycle of reinfection. Called SC, the infection spreads its working parts across website files, the database, and server memory, allowing surviving components to restore those removed. The investigation does not establish the original entry point or the number of affected […]
Coverage Details
Bias Distribution
- There is no tracked Bias information for the sources covering this story.
Factuality
To view factuality data please Upgrade to Premium








