WordPress Backdoor Rebuilds Itself After Cleanup Using Files, Database, and Shared Memory
Sucuri details SC, a self-healing WordPress backdoor that rebuilds from files, the database, and RAM.
Sucuri analyzed a WordPress backdoor dubbed SC that stores the same payload in at least eight places across drop-ins, a fake hyper-engine-kit plugin, the theme, the database, and System V shared memory, so each copy can restore the others. The obfuscated payload hides from the admin UI, uses the Ethereum blockchain for command and control, creates a hidden administrator, runs PHP, and can inject JavaScript such as skimmers. Initial access is unknown. Separately, unauthenticated SQL injection CVE-2026-1581 in wpForo Forum through version 2.4.14 is being exploited, with fewer than 20 attempts from five IPs since July 3.