SC WordPress Malware Self-Heals; wpForo Flaw Lightly Probed
Sucuri’s self-healing SC WordPress malware restores itself from files, database, memory, and Ethereum; wpForo CVE-2026-1581 drew fewer than 20 attempts.
Sucuri analyzed a WordPress malware family called SC whose payload is replicated so that any surviving copy can restore the others within seconds of partial cleanup. Locations described across the reports include a .user.ini auto_prepend_file trigger, hidden PHP and a string-table loader using a positional substitution cipher, db.php and advanced-cache.php drop-ins carrying gzip and base64 payloads, a functions.php theme injection, WordPress cron, wp_options rows, ZIP archives, System V shared memory, a must-use plugin, and a normal plugin that Sucuri presents as a fake caching tool while The Hacker News names hyper-engine-kit. Commands come from smart contracts queried through public Ethereum JSON-RPC gateways—roughly twenty, according to Cyber Security News—and described capabilities include hiding administrator accounts, collecting session tokens, forging authentication cookies, removing security plugins, running PHP, and injecting browser scripts that could skim checkouts. Sucuri and The Hacker News say at least eight locations span files, the database, and shared memory, whereas GBHackers says at least eight file-based components plus further copies in the database, memory, archives, and cron; Sucuri also says a fake settings page sits in plain sight, while GBHackers and The Hacker News say the payload hides from the admin UI. Initial access and the number of affected sites remain unknown, and cleanup advice differs between removing every copy in the correct order and neutralizing the loader before deleting all recovery copies together. Separately, The Hacker News reports that unauthenticated SQL injection CVE-2026-1581 in wpForo Forum through version 2.4.14 is being exploited, with Previdian seeing fewer than 20 attempts from five IP addresses since July 3.
- Sucuri documented SC, a WordPress malware family that stores the same payload in at least eight places and can rebuild deleted components within seconds.
- Reported persistence spans .user.ini auto_prepend_file, a positional-substitution string-table loader, db.php and advanced-cache.php drop-ins (gzip and base64), theme functions.php, cron, wp_options, ZIP archives, a must-use plugin, and a…
- Command and control uses Ethereum smart contracts queried through public JSON-RPC gateways—about twenty, per Cyber Security News—including eth_call requests.
- Reported behavior includes hiding administrator accounts, collecting session tokens, forging authentication cookies, disabling security plugins, running PHP, and injecting checkout-skimming JavaScript.
- Initial access and the number of affected sites were not identified.
- Sources disagree on visibility (Sucuri: a fake settings page in plain sight; GBHackers and The Hacker News: hidden from the admin UI) and on whether “eight” counts mixed locations or file-based components only.
- Cleanup guidance differs: Sucuri says remove every copy in the correct order; Cyber Security News says neutralize the loader before deleting all recovery copies together.
- Separately, The Hacker News reports unauthenticated SQL injection CVE-2026-1581 in wpForo Forum through 2.4.14, with Previdian recording fewer than 20 attempts from five IPs since July 3.
Coverage timelineoldest first · each row is one article
- · 2d agoSC WordPress Malware: A Self-Healing Mesh of Loaders, Drop-Ins, and a Blockchain-Controlled Backdoor
Sucuri Blog· 48
Sucuri documents SC, a self-healing WordPress malware mesh persisting across files, database, and shared memory, regenerating within seconds of cleanup.
- · 1d agoSC WordPress Malware Rebuilds Itself After Removal Using Database and Memory Persistence
GBHackers· 63
SC WordPress malware rebuilds deleted backdoors from files, the database, cron, and shared memory.
- · 1d agoWordPress Malware Comes Back After Removal Using a Self-Healing Backdoor
Cyber Security News· 56
Vulnerabilities in this storyAll →
- CVE-2026-15817.52%The wpForo Forum plugin for WordPress is vulnerable to time-based SQL Injection via the 'wpfob' parameter in all versions up to, and including, 2.4.14 due to…published · WordPress
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-1581 | The wpForo Forum plugin for WordPress is vulnerable to time-based SQL Injection via the 'wpfob' parameter in all versions up to, and including, 2.4.14 due to… The wpForo Forum plugin for WordPress is vulnerable to time-based SQL Injection via the 'wpfob' parameter in all versions up to, and including, 2.4.14 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. |