Crypto-Powered WordPress Malware Refuses to Die
9 Articles
9 Articles
A variant of WordPress malware, called SC, uses about 20 public Ethereum gateways and keeps copies of its load on different components to make it difficult to remove it. Sucuri also warns that it can steal administrator session tokens, disable security tools and insert JavaScript capable of capturing payment data.
🚨 SC malware, which uses Ethereum infrastructure, poses a persistent threat to WordPress sites. 🧩 Sucuri announced that the malicious payload is present in at least eight different locations simultaneously. 🔐 Attackers can hijack administrator sessions and maintain access through $ETH-linked RPC gateways. 🛒 The malware poses a data collection risk by adding JavaScript to the payment step on e-commerce sites. Read More: WordPress malware usin…
Crypto-Powered WordPress Malware Refuses to Die
A highly persistent WordPress malware strain is using Ethereum infrastructure to stay alive, with redundant copies scattered across compromised sites allowing it to rebuild itself even after attempted cleanup.
WordPress Backdoor Rebuilds Itself After Cleanup Using Files, Database, and Shared Memory
Ravie LakshmananOct 01, 2026Vulnerability / Web Security Cybersecurity researchers have shed light on a WordPress compromise in which threat actors deployed multiple persistence mechanisms to ensure that the final payload kept returning without having to infect the site again. The backdoor has been codenamed SC after the "SC_" markers present in the injected content. Sucuri
Coverage Details
Bias Distribution
- There is no tracked Bias information for the sources covering this story.
Factuality
To view factuality data please Upgrade to Premium








