Self-healing SC backdoor rebuilds itself on WordPress sites after cleanup

Sucuri researchers detailed SC, a WordPress backdoor that keeps copies in at least eight places across files, the database and shared memory, each able to rebuild the others.

Self-healing SC backdoor rebuilds itself on WordPress sites after cleanup

At a glance

  • Sucuri found the SC backdoor during cleanups where it returned within seconds of every removal
  • Copies live in loaders, db.php and advanced-cache.php drop-ins, a theme, plugins, an options row and System V shared memory
  • The malware uses public Ethereum RPC gateways for command and control and creates hidden administrator accounts
  • Sucuri says the order of cleanup steps matters more than the individual deletions

Researchers at website security firm Sucuri have documented a WordPress backdoor, dubbed SC, that rebuilds itself after cleanup by keeping copies of its payload in files, the database and shared memory at the same time. According to The Hacker News, which reported the findings on October 1, 2026, the payload "lives in at least eight places at once" and every one of those places can restore the others, which makes ordinary file-by-file removal ineffective.

What happened

Sucuri researcher Gabriel Barbosa wrote in an analysis published on September 30 that the malware was identified during site cleanups in which the same backdoor kept returning within seconds of every removal. The name SC comes from SC_ markers found in the injected content. Sucuri describes the infection as a self-healing mesh: deleting the plugin causes a drop-in to rewrite it, and deleting the drop-in causes the theme to restore it.

The Hacker News noted that it is currently not known how the malware reached the affected sites. The outlet listed typical entry points for such infections, including known flaws in WordPress, plugins and themes, weak login credentials, supply chain attacks on popular plugins and insecure upload features.

Technical details

According to Sucuri, the eight file-based components include a .user.ini file that sets an auto_prepend_file directive, a visible loader and a hidden dot-prefixed loader in wp-content, the db.php and advanced-cache.php drop-ins, an injected block in a theme's functions.php, a must-use plugin and a matching copy in the regular plugins folder. The Hacker News listed paths such as wp-content/c1b12371.php, wp-content/.c1b12371.php, wp-content/themes/khorshidi/functions.php and wp-content/mu-plugins/hyper-engine-kit.php.

Sucuri said the malware also persists off disk. The full payload is stored as a gzip and base64 blob in a randomly named options row in the database, a System V shared memory segment holds PHP code that survives file and database cleanup, and scheduled tasks trigger redeployment. The company added that related variants use database triggers to recreate administrator accounts.

Instead of hardcoded servers, the backdoor carries a list of roughly twenty public Ethereum RPC gateways for command and control, Sucuri said, warning that all of them must be blocked together. The payload hides itself from the admin plugin list, fingerprints the site, adopts or creates a hidden administrator account and exposes a beacon through a special request parameter. The Hacker News reported that it can also fetch arbitrary JavaScript to target site visitors with skimmers or other malware, and deactivate or delete specific plugins.

Who is affected

The threat concerns WordPress site owners and hosting providers. Sucuri did not publish a count of infected sites in the material reviewed.

What to do

Sucuri stresses that the order of operations matters more than the individual deletions. Its recommended sequence is to neutralise the prepend directive first, keeping in mind that PHP may cache it for 300 seconds, then clear the database, shared memory and transient copies, remove scheduled tasks and database triggers, delete hidden administrator accounts, remove all malicious files in a single pass and rescan. Indicators include unexpected code in db.php or advanced-cache.php, .user.ini directives pointing to hidden files, matching fake plugins in mu-plugins and plugins, large blobs in the options table and outbound requests to Ethereum RPC gateways. Sucuri also recommends keeping software patched, using a web application firewall and treating any reappearance as unfinished cleanup.

Sources

This story is based on the sources listed above. Always check the vendor’s official advisory before acting on critical systems.