WordPress “SC” self-healing mesh backdoor (Sucuri): 8+ persistence points + Ethereum C2 — THN 1 Oct
The Hacker News (1 October 2026) amplifies Sucuri research on a WordPress malware family codenamed SC (from “SC_” markers) described as a blockchain-controlled “self-healing mesh.” Identical backdoor payload is planted in at least eight places — including wp-content/db.php drop-in, a theme-resident twin (e.g. khorshidi/functions.php), fake plugin hyper-engine-kit (and a second copy), database storage, and System V shared-memory segments with a fixed numeric key — so deleting any one copy lets another rewrite the set on next page load or via cron. Code uses a substitution-cipher decoder (no readable function names). Capabilities: hide from plugins screen/update checks; C2 via Ethereum blockchain; fingerprint site; fetch arbitrary JavaScript (skimmers/malware); run PHP; deactivate/delete plugins. Shared-memory copy can survive disk+DB cleanup and on shared hosting may be owned by another account. Initial access vector not confirmed (typical WP plugin/theme flaws, weak creds, supply chain). Sucuri primary blog was JS-challenge blocked from desk at pass time — wire-primary THN until Sucuri fetch recovers. Distinct from desk greynoise-kapibala-wordpress-20260921 and admin-menu-editor-pro-supply-chain-20260915.
- Product
- WordPress sites (SC mesh backdoor: db.php drop-in, theme functions, fake plugin, DB, SysV shm; Ethereum C2)
- Versions
- n/a — malware/persistence toolkit (not a single CVE); initial access vector unconfirmed per Sucuri/THN
- Exploited in Australia?
- unknown
- Patch to
- No single CVE patch. Incident response: assume multi-location rebuild — clean files AND database AND check SysV shared memory; remove db.php drop-in, fake hyper-engine-kit plugin, theme twin loaders, SC_ DB injections, and malicious cron hooks; rotate all WP/DB/hosting credentials; audit outbound Ethereum/RPC callbacks; restore from known-good backup when available. Harden: keep core/plugins/themes current; disable unused plugin install; MFA on admins; file-integrity monitoring covering drop-ins and mu-plugins.
Primary: The Hacker News — WordPress SC self-healing mesh backdoor / Ethereum C2 (1 Oct 2026) · Vendor: Sucuri Blog — self-healing mesh / blockchain-controlled backdoor (linked from THN; primary research)
