Researchers at Sucuri have documented a WordPress backdoor dubbed SC that acts as a "self-healing mesh." The malware keeps its payload in at least eight places, including files, the database, and System V shared memory, and any of those locations can rebuild the others. This circular design means there is no single point of failure an administrator can remove to stop the infection.

The components include a .user.ini auto-prepend loader, a hidden dot-prefixed file, a fake plugin installed in both mu-plugins and regular plugins, a db.php drop-in, an advanced-cache.php drop-in, and a theme functions.php file. The code is obfuscated with a substitution cipher and has no readable function names. On servers that support System V shared memory, the payload lives in RAM, surviving file deletion and database cleanup, and on shared hosting it may even be owned by a different account.

Once running, the backdoor can hide itself from the admin plugins screen, communicate with a command-and-control server via the Ethereum blockchain, fingerprint the infected site, create a hidden administrator account, and run a reinfection loop. It can also inject arbitrary JavaScript to target visitors with skimmers, execute PHP code, and deactivate or delete specific plugins. The initial access vector is not yet known, but the researchers note that typical WordPress compromises involve plugin vulnerabilities, weak credentials, supply-chain attacks, or insecure upload features.