Cybersecurity researchers have uncovered a sophisticated WordPress backdoor designed to survive cleanup attempts by storing copies of itself across website files, the database and server memory.
The malware, tracked as SC because of the “SC_” markers found in its injected code, uses several persistence mechanisms that allow one surviving component to recreate the others. Security firm Sucuri described the technique as a “self-healing mesh,” with the malware also using the Ethereum blockchain for command-and-control communication.
Researchers found that the backdoor can exist in at least eight different locations at the same time. These include WordPress configuration files, PHP loaders, database content, caching files, a compromised theme, multiple copies of a malicious plugin and System V shared memory.
One component uses the “.user.ini” file to configure “auto_prepend_file”, allowing a malicious loader to run before PHP requests. Other files in the WordPress content directory then locate hidden components and restore the malware when parts of the infection have been removed.
The malware also places a copy of itself in “db.php”, which is loaded during WordPress startup. If the malicious plugin disappears or becomes too small, the file can decode and deploy another copy. A similar mechanism exists in “advanced-cache.php”, which can restore the malware from several different sources, including another plugin copy, a ZIP archive, the database and shared memory.
A compromised theme file provides another recovery mechanism, while the malicious “hyper-engine-kit.php” payload is installed in both the must-use plugins directory and the regular plugins directory. This redundancy makes removing the infection considerably more difficult because deleting one copy can trigger another copy to restore it.
The malware also attempts to hide its presence from WordPress administrators and update checks. It communicates with a command-and-control server through the Ethereum blockchain, collects information about the infected website and can download additional payloads.
Once active, the backdoor can create a hidden administrator account, execute PHP code, inject JavaScript into websites and target visitors with malicious scripts such as skimmers. It can also deactivate or remove selected WordPress plugins.
One particularly persistent feature is its use of System V shared memory. On systems that support it, the malware can store PHP code in a shared-memory segment identified by a fixed numeric key. Because the data exists in RAM rather than as a normal website file, deleting infected files and cleaning the database may not be enough to remove the infection.
The malware also registers WordPress cron hooks, including randomly generated names and a known fetch hook. These scheduled tasks can trigger the reinfection process without relying on normal visitor traffic.
Researchers have not yet determined how SC initially gains access to WordPress sites. Possible entry points include vulnerabilities in WordPress core, plugins or themes, stolen or weak credentials, compromised software supply chains and insecure upload functionality that allows attackers to place PHP web shells on a server.
The discovery highlights how some WordPress compromises can extend far beyond a single malicious file. In this case, multiple copies of the backdoor are connected so that surviving components can reconstruct the rest of the infection.
The disclosure comes as a separate high-severity vulnerability in the wpForo Forum WordPress plugin is being actively exploited. Tracked as CVE-2026-1581, the unauthenticated SQL injection vulnerability has a CVSS score of 7.5 and affects versions up to and including 2.4.14.
According to telemetry from Previdian, fewer than 20 exploitation attempts targeting the wpForo vulnerability have been observed since July 3, 2026. The activity has been linked to five attacker IP addresses located in Bulgaria, Switzerland, France, the United States and Yemen.
If this article helped you, please consider supporting our work. Every small contribution keeps Abijita.com independent and running.
WordPress Backdoor Can Rebuild Itself After Cleanup Using Eight Persistence Layers



