Wordfence Details Self-Healing WordPress Must-Use Plugin Backdoor with Ethereum-Based C2
Wordfence analyzed a WordPress backdoor installed as a must-use plugin under 4,000+ filenames that self-repairs from a database copy, steals admin passwords and payment/cloud secrets, and fetches its command-and-control servers from Ethereum smart contracts…
Wordfence's Threat Intelligence Team described malware discovered during a mid-June 2026 site cleanup. The implant installs as a WordPress must-use plugin — so it loads on every request — and has been observed under more than 4,000 filenames. It hides from the admin dashboard and plugin/health screens, creates or password-resets concealed administrator accounts, and hooks the authentication flow to capture plaintext administrator passwords. The malware collects WooCommerce data and harvests secrets from wp-config.php, .env, and Git configuration files, including Stripe, Braintree, Authorize.Net, and AWS keys. It is self-healing: if deleted, it restores itself from a copy stored in the database, and it can remove security plugins. Command-and-control uses EtherHiding, querying Ethereum smart contracts across 21 public JSON-RPC endpoints to retrieve attacker HTTP servers. The implant can also inject JavaScript into visitor-facing pages and spread to other WordPress sites hosted on the same server. Wordfence released a detection signature on June 23, 2026. All three reports agree on the core facts; no conflicting figures were reported.
- Malware sample found by Wordfence during a mid-June 2026 site cleanup.
- Installed as a WordPress must-use plugin, observed under more than 4,000 different filenames.
- Loads on every request and hides from the admin dashboard and plugin/site-health screens.
- Self-healing: restores itself from a database copy if deleted and can remove security plugins.
- Creates or password-resets hidden administrator accounts.
- Hooks authentication to capture plaintext administrator passwords at login.
- Harvests WooCommerce data and secrets from wp-config.php, .env, and Git config, including Stripe, Braintree, Authorize.Net, and AWS keys.
- Obtains C2 addresses via EtherHiding by querying Ethereum smart contracts over 21 public JSON-RPC endpoints.
Coverage timelineoldest first · each row is one article
- · 4d agoInside a Malicious, Stealthy WordPress Must Use Plugin
Wordfence· 48
Wordfence analyzed WordPress malware installed as a must-use plugin that self-heals to survive removal.
- · 4d agoStealthy WordPress Malware Uses Must-Use Plugin and Ethereum EtherHiding for Persistent Backdoor Access
GBHackers· 60
Wordfence details a WordPress must-use plugin backdoor that steals credentials and hides C2 on Ethereum.
- · 4d agoWordPress Malware Uses Hidden Plugin and Blockchain C2 to Stay Undetected
Cyber Security News· 68