- Security researchers have uncovered a WordPress malware codenamed SC that uses the Ethereum blockchain for command-and-control communication, making removal extremely difficult.
- The backdoor is a “self-healing mesh” that persists across at least eight locations—including files, the database, and shared memory—rebuilding itself from any surviving copy on the next page load.
- Attackers can take full control of infected sites, inject skimmers, and create hidden admin accounts, all while hiding from plugin screens and update checks.
- Separately, a high-severity unauthenticated SQL injection flaw (CVE-2026-1581) in the wpForo Forum plugin is being actively exploited by five attacker IPs since July 2026.
On October 1, 2026, cybersecurity researchers at Sucuri disclosed a sophisticated WordPress compromise that deploys a blockchain-controlled backdoor with unprecedented persistence. The malware, codenamed SC after the “SC_” markers in its injected content, creates a “self-healing mesh” that lives in at least eight places at once, spanning files, the database, and shared memory.
According to security researcher Gabriel Barbosa, “Delete the plugin and a drop-in rewrites it. Delete the drop-in and the theme rewrites it. Clean every file on disk, and the next page load restores the whole set from the database or from a shared-memory segment.” The infection uses a decoder with a substitution cipher, making its function names unreadable.
Regardless of the entry method, the backdoor communicates with its command-and-control server via the Ethereum blockchain. It fingerprints the infected site, retrieves additional payloads, and creates a hidden administrator account. On servers supporting System V shared memory, the payload lives in RAM, surviving file deletion and database cleanup, and can even be owned by a different account on shared hosting.
The SC backdoor registers cron hooks with randomized names, enabling redeployment on schedule via system cron. Meanwhile, the wpForo Forum plugin is under active exploitation for CVE-2026-1581, an unauthenticated SQL injection vulnerability. According to telemetry data from Previdian, fewer than 20 exploitation attempts have been observed since July 3, 2026, originating from five unique IP addresses in Bulgaria, Switzerland, France, the U.S., and Yemen.
✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.
Previous Articles:
- ARK Invest Sells AMD, Buys $81M Nvidia in Portfolio Shake-Up
- Citi expects $5B crypto ETF inflows, raises Bitcoin target
- Tokenized markets show distinct patterns from traditional: Dune
- DogeOS opens public testnet for Dogecoin EVM apps on Sept 30
- Bitcoin ETFs 9th straight inflow day $66M beats Aug’s streak
