ConicPlex

Start Your Project

A laptop glowing with WordPress blue light on a dark desk at night, surrounded by several identical old brass keys half hidden under a notebook, symbolizing a backdoor that hides duplicate copies of itself.

On this Page

WordPress Backdoor SC Survives Cleanup by Hiding in Files, Database, and Memory

Sucuri documented a self-healing WordPress backdoor called SC that rebuilds itself from eight hiding spots, including shared memory, after a normal cleanup.

Aftab Memon

October 3, 2026

Sucuri published research on September 30, 2026 describing a WordPress backdoor, nicknamed SC, that survives a normal cleanup by hiding in eight places at once: five separate files, a database options row, a scheduled task, and a shared memory segment on the server itself. Delete the obvious plugin file and the other seven copies quietly rebuild it. The malware was found during real incident response work, not a lab test, and it talks to its command infrastructure through public Ethereum RPC gateways instead of a server an investigator could just block.

What Sucuri Found

Security analyst Gabriel Barbosa named the backdoor SC after markers left in the injected code. According to Sucuri’s writeup, the payload lives across a .user.ini file that silently auto-loads a hidden loader, a visible shim at wp-content/c1b12371.php paired with a hidden version of the same file, the wp-content/db.php and wp-content/advanced-cache.php drop-ins WordPress trusts without question, an injected block in the active theme’s functions.php, and a copy of the backdoor installed twice, once as a must-use plugin and once as a regular one, under the name hyper-engine-kit.

Each of those locations can read a compressed, base64-encoded copy of the full payload out of a randomly named row in the wp_options table, or out of a System V shared memory segment that lives in RAM and outlives both a file wipe and a database cleanup. Database triggers quietly recreate hidden administrator accounts if they get deleted. That is why, as Barbosa put it, cleaning one location fails until every copy is purged in the same pass.

Why It Is Hard to Block

The command-and-control layer is the more unusual part. Instead of phoning home to a domain a host or firewall could blacklist, SC reads instructions from a smart contract through roughly twenty public Ethereum RPC gateways. Blocking the one gateway seen in a log leaves the other nineteen working fine, and none of them look unusual to a web host, since they are the same infrastructure crypto wallets use all day.

What WordPress Site Owners Should Actually Do

Sucuri’s own guidance, and the broader pattern confirmed by The Hacker News’s coverage of the same research, comes down to a few concrete steps rather than a single file delete:

  • Neutralize the auto_prepend_file directive in .user.ini before touching anything it points to, or the loader just reloads itself mid-cleanup.
  • Check the wp_options table for unfamiliar, randomly named rows holding compressed data, not just the usual suspects.
  • Remove all eight components in a single pass rather than one at a time, since surviving copies will simply rewrite the ones already deleted.
  • Audit scheduled tasks, database triggers, and the admin user list afterward, since this is exactly where SC hides its recovery hooks.
  • Treat any file reappearing after cleanup as a sign the job is incomplete, not as a new, unrelated infection.

This is also a reasonable argument for not treating WordPress security as a one-time fix. A site that gets this kind of deep, multi-location compromise usually got in through something ordinary, an outdated plugin, a weak admin password, a forgotten staging copy left public, well before the backdoor itself showed up. Regular WordPress maintenance and development work that keeps plugins current and reviews the admin user list on a schedule closes most of the doors this kind of malware walks through in the first place.

It is also a reminder that WordPress’s own ecosystem has been tightening the other side of this problem lately. Automatic update gates like the one covered in WordPress.org’s new auto-blocking of high-risk plugin updates are aimed at the supply side. Research like Sucuri’s is what catches what gets through anyway.

Sources

Aftab Memon is a Senior WordPress Developer at ConicPlex, working across everything from plugin conflicts and theme customization to full site builds on Elementor and WooCommerce. He spends most of his time in the parts of WordPress that don’t show up in a features list: hosting quirks, hook priority, the difference between a plugin that works in isolation and one that survives a real production stack. He writes here about what actually holds up once a WordPress site is live and being run by a non-technical client, not just what works in a demo.

Leave a Reply

Your email address will not be published. Required fields are marked *

Keep reading

News & Updates

A laptop glowing with a soft magenta light next to an ID keycard on a wooden desk, symbolizing a WordPress admin access vulnerability

Elementor Patches a Critical CSRF Flaw That Could Hand Attackers Admin Access (CVE-2026-62062)

A CSRF flaw in Elementor 4.3.0 and 4.3.1 (CVE-2026-62062, CVSS 8.8) let attackers create admin accounts with one click. Patched…

Aftab Memon

October 2, 2026

Plugins

Stack of to-do list task cards with checkboxes in front of a faded kanban board, illustrating WordPress dashboard to-do list and task management plugins

How to Add a To-Do List to Your WordPress Dashboard (4 Plugins Compared)

Compare four real WordPress plugins for a dashboard to-do list or task board, from a simple single-person widget to full…

Husen Memon

October 2, 2026

Plugins

Flat illustration of a purple clock overlapping a shopping cart blocked by a striped barrier, representing WooCommerce checkout restricted to business hours

Best WooCommerce Plugins to Disable Checkout outside Business Hours: 4 Real Options Compared

WooCommerce has no setting for “only accept orders while we’re open.” If you run a restaurant, a bakery, a local…

Sajil Memon

October 2, 2026

WhatsApp
Husen Memon
Husen Memon
Typically replies instant