SC WordPress Malware – Self-Healing Backdoor Persistence and Cleanup
Sucuri documented SC WordPress malware, a self-healing backdoor that persists across files, database options, shared memory, cron, and database triggers. This guide covers indicators and the required cleanup order.
Sucuri has documented a persistent WordPress malware family called SC that can rebuild itself from files, the database, shared memory, scheduled tasks, and database triggers. Removing one visible backdoor is not enough: surviving components can restore the full infection on the next request.
The campaign is notable for its circular persistence design. Sucuri recovered at least eight cooperating components, including PHP auto-prepend configuration, WordPress drop-ins, an injected theme block, duplicate fake plugins, an encoded database copy, a System V shared-memory segment, and scheduled redeployment. The backdoor also uses public Ethereum RPC gateways as resilient command-and-control transport.
Incident summary
| Threat | SC WordPress malware family |
|---|---|
| Type | Self-healing backdoor and persistence mesh |
| Authentication required | Not applicable once the site is compromised |
| Primary impact | Remote control, hidden administrator access, credential/session theft, security-plugin removal, PHP deployment, and possible checkout skimming |
| Persistence locations | Files, WordPress options, shared memory, WP-Cron/system cron, and database triggers |
| Disclosure | Sucuri, September 30, 2026 |
| CVE | None assigned; this is a malware campaign and cleanup advisory |
How the persistence mesh works
The infection does not rely on a single malicious file. Each surviving component can recreate others, which explains why incomplete cleanups appear successful and then fail seconds later.
- PHP auto-prepend configuration: a directive in
.user.ini,php.ini, or.htaccessforces a loader to run before normal PHP requests. - Visible and hidden loaders: a plainly named PHP shim includes a hidden dot-prefixed loader under
wp-content. Names vary between infections. - WordPress drop-ins: malicious
wp-content/db.phpandwp-content/advanced-cache.phpcopies execute early and can restore the payload. - Theme injection: a bounded malicious block appended to the active theme’s
functions.phprewrites the backdoor when it is removed. - Duplicate plugin copies: the same payload is installed as both a must-use plugin and a normal plugin. Sucuri’s sample used the name
hyper-engine-kit.php, but defenders should expect names to vary. - Database storage: an options row with a random name stores a compressed and encoded payload that a drop-in can write back to disk.
- Shared memory: a System V shared-memory segment can retain PHP code even after files and database rows are cleaned.
- Scheduled and database persistence: malicious cron hooks redeploy the infection, while related variants use database triggers to recreate an administrator.
Backdoor capabilities
According to Sucuri’s analysis, the malware hides its plugin and administrator entries from normal WordPress views. It fingerprints the site, collects WordPress and plugin versions, theme and must-use plugin information, path hashes, and administrator session tokens, then contacts attacker-controlled infrastructure resolved through public Ethereum RPC gateways.
Commands can deliver front-end JavaScript, install new PHP, disable or delete security plugins, create or elevate a hidden administrator, and forge authentication cookies. On WooCommerce sites, injected front-end JavaScript creates a direct payment-skimming risk.
Indicators of compromise
- Unexpected PHP in
wp-content/db.phporwp-content/advanced-cache.php, especially code carryingSC_-style markers or guard constants. - A suspicious bounded block appended to the active theme’s
functions.php. - An
auto_prepend_filedirective in.user.ini,php.ini, or.htaccessthat points to an unfamiliar PHP file. - Matching fake-plugin payloads under both
wp-content/mu-pluginsandwp-content/plugins. - Randomly named ZIP archives under
wp-content, uploads, or theme directories. - Large compressed or base64-like values in randomly named WordPress options, plus options or transients with an
sc_-style prefix. - Unexpected PHP stored in a System V shared-memory segment.
- A privileged user that is missing from the normal WordPress Users screen.
- Unexpected outbound connections from the web server to multiple public Ethereum RPC gateways.
Safe initial checks
Run these commands from the WordPress document root and preserve their output before changing anything:
wp plugin list --status=must-use
wp plugin list --status=active
wp theme list --status=active
wp user list --role=administrator --fields=ID,user_login,user_email,user_registered
wp cron event list
wp core verify-checksums
Search for prepend directives and executable files in locations that normally contain media:
grep -RIn "auto_prepend_file" .user.ini php.ini .htaccess wp-content 2>/dev/null
find wp-content/uploads -type f \( -name '*.php' -o -name '*.phtml' -o -name '*.phar' \) -print
find wp-content -type f -name '*.zip' -print
Use read-only database queries to review suspicious options and database triggers. Replace wp_ only if the site uses a different table prefix:
wp db query "SELECT option_name, LENGTH(option_value) AS bytes FROM wp_options WHERE option_name LIKE 'sc\_%' OR LENGTH(option_value) > 500000 ORDER BY bytes DESC LIMIT 100;"
wp db query "SELECT TRIGGER_NAME, EVENT_MANIPULATION, EVENT_OBJECT_TABLE, ACTION_TIMING FROM information_schema.TRIGGERS WHERE TRIGGER_SCHEMA = DATABASE();"
Large options and database triggers are not automatically malicious. Record values, timestamps, hashes, ownership, and related logs before removal.
Cleanup order matters
Do not begin by deleting the obvious backdoor files. If an auto-prepend setting still points to a removed target, cached PHP configuration can break every request. If an off-disk copy remains, the infection can immediately rebuild itself.
- Contain execution. Put the site in controlled maintenance, preserve logs and a forensic copy, and restrict public access. Neutralize the auto-prepend target with an inert file before removing the directive.
- Remove off-disk persistence first. Identify and remove the malicious option row, related control options and transients, the shared-memory segment, malicious cron hooks, and unauthorized database triggers. Shared-hosting customers may need their host to remove a segment owned by another account.
- Remove hidden access. Identify the concealed administrator from the database and logs, preserve evidence, then remove it and any orphaned references.
- Clean the filesystem in one pass. Remove the loaders, both fake-plugin copies, restore ZIPs, and malicious drop-ins. Remove only the bounded injected block from a legitimate theme file, or replace the theme with a verified clean copy.
- Reinstall trusted software. Replace WordPress core, plugins, and themes from authoritative packages rather than trying to repair obfuscated malware in place.
- Close the initial entry point. Patch or remove vulnerable components and correct exposed credentials, permissions, or control-panel access.
- Rotate secrets after cleanup. Change WordPress, hosting, SFTP/SSH, database, API, payment, and administrator credentials; invalidate active sessions and regenerate WordPress salts.
- Verify repeatedly. Rescan the site and monitor affected paths, options, users, cron hooks, database triggers, and outbound traffic. Any reappearance means a persistence point or original entry route remains.
When to involve the hosting provider
Escalate to the host when shared memory cannot be enumerated or removed by the account, PHP-FPM configuration caching prevents a safe auto-prepend change, database triggers require elevated privileges, or outbound RPC traffic must be blocked at the network layer. A site owner should not attempt live shared-memory or database-trigger removal without a validated backup and a clear rollback path.
Sources
- Sucuri: SC WordPress Malware analysis and cleanup order
- WordPress Developer Resources: Hardening WordPress
- WP-CLI: Verify WordPress core checksums
WPDeeply did not discover this malware. This advisory summarizes Sucuri’s public technical analysis and provides defensive detection and remediation guidance. File names and persistence details can vary by infection.