Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

In a WordPress compromise analyzed by Sucuri, malware called SC persisted in files, the database and shared memory, allowing surviving components to restore ones that had been removed. Its backdoor also used public Ethereum RPC gateways to fetch instructions. That explains why deleting visible files alone could fail; it does not mean Ethereum was compromised or that every infected site suffered payment theft.

What Sucuri found in the SC case

Sucuri security analyst Gabriel Barbosa described the incident on September 30, 2026, after encountering the backdoor during website cleanup and seeing it return seconds after removals. The label SC comes from “SC_” markers in injected content. In the examined infection, Sucuri found payload copies in at least eight locations. That is a finding about this case, not a measure of how common SC is or a fixed blueprint for every infection. Read Barbosa’s analysis.

Where it persisted Examples Sucuri described Why it matters
Configuration and loader files A .user.ini directive setting auto_prepend_file, plus loader or shim files The directive can make PHP load malicious code automatically during requests.
WordPress drop-ins and theme code db.php, advanced-cache.php, and a marked block in the active theme’s functions.php These locations can execute as part of normal site or caching behavior.
Plugin directories Matching fake-plugin payloads in mu-plugins and plugins Copies in separate locations can preserve an alternate route to execution.
Database and memory An encoded payload in a database option and a System V shared-memory segment These copies are not ordinary plugin or theme files, so a file-only cleanup can miss them.
Other persistence mechanisms in related variants Scheduled tasks and database triggers They can restore or run malicious code even after visible files are removed.

File names can vary between sites. A suspicious file or code marker is an indicator to investigate, not by itself proof that every listed component is present.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How the blockchain command channel worked

The analyzed payload included selectors and a list of roughly twenty public Ethereum RPC gateways that it could query for smart-contract instructions. RPC gateways are services for interacting with a blockchain; Sucuri’s finding was that the malware abused legitimate public infrastructure as a command channel. It was not evidence of an attack on the Ethereum network. Because the payload had multiple gateway choices, blocking one observed endpoint alone may leave alternatives available.

#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

What the backdoor could do

Sucuri reported that the payload fingerprinted the WordPress environment and collected details such as site versions, paths and administrator session tokens, then sent encrypted data. It could receive front-end JavaScript or PHP, deactivate and delete security plugins, and create or hide privileged administrator accounts.

On an online store, injected checkout JavaScript could capture payment information. The report describes that as a capability and risk, not a confirmed outcome for every site in the case. The impact depends on what code was delivered and where it ran.

Rank #2
Cryptnox FIDO2 Security Key with MIFARE DESFire NFC Smart Card for 2FA MFA
  • HARDWARE 2FA AND MFA: FIDO Alliance Certified FIDO2 v2.1 with CTAP2 plus legacy U2F and CTAP1 for strong two-factor login and passwordless sign-in on services that support security keys
  • BUILDING ACCESS ON ONE CARD: MIFARE DESFire EV2 4K applet with AES encryption adds office door and physical access control alongside digital authentication
  • CERTIFIED SECURE ELEMENT: An NXP Common Criteria EAL6+ certified secure controller and Java Card platform protects your keys on a tamper-resistant chip
  • DUAL INTERFACE SMART CARD: Contactless NFC ISO 14443 plus ISO 7816 contact reader support in an ISO 7810 ID-1 format that is passive and needs no battery
  • SWISS ENGINEERED DESIGN: Built by Cryptnox as a single card for authentication and access control and backed by a 2 year warranty

Signs worth investigating

Sucuri’s indicators are specific to its SC analysis, not a complete signature for all WordPress malware. Investigate unexpected findings such as:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • SC-style code in wp-content/db.php or advanced-cache.php.
  • A marked injected block in the active theme’s functions.php, or an unexpected auto_prepend_file directive in .user.ini.
  • A fake or unfamiliar plugin duplicated between mu-plugins and plugins.
  • Randomly named ZIP archives that appear to be restore bundles.
  • A large encoded blob in the WordPress options table or an unexpected PHP segment in shared memory.
  • Hidden or otherwise suspicious administrator accounts.
  • Outbound connections from the web server to public Ethereum RPC gateways.

Any one sign needs context. Compare files and settings with known-good backups, review account and server activity, and have a qualified incident responder or hosting provider help interpret findings if you cannot establish what is legitimate.

Rank #3
Sale
Thetis Nano-A FIDO2 Security Key Hardware Passkey Device with USB Type A, TOTP/HOTP, FIDO2.0 Two Factor Authentication 2FA MFA, Works with Windows/mac/iOS/Android/Linux/Gmail/Facebook/GitHub/Coinbase
  • Ultra-Compact FIDO2 Security Key - Plug-and-stay or carry on a keychain. This USB-A hardware security key offers portable, always-on protection for desktop and mobile use. (Item Size: 0.75 X 0.74 IN x 0.25 IN)
  • USB-A Hardware Key for All Devices - Works with USB-A ports on PC, Mac, Android, and other laptop/notebook device. Enables secure, cross-platform login with FIDO2.0 passkey support.
  • FIDO Certified Security Key - Meets FIDO and FIDO2 standards. Works with Google, Microsoft, GitHub, Dropbox, and more. Please check service compatibility before purchase.
  • Passwordless Login with Passkey - Supports passkey login via WebAuthn and CTAP2. Enjoy password-free sign-ins where supported. Not all websites or services currently support passkeys.
  • Advanced Multi-Factor Authentication - Offers 200 FIDO2 passkey slots and 50 OATH-TOTP slots. Strong, flexible 2FA/MFA support across various apps and authentication platforms.

Why malware can return after file cleanup

A file deletion removes only that copy. In this case, a surviving loader, database payload, memory segment, scheduled task or trigger could preserve another execution path or recreate a removed component. Sucuri’s description of the infection as a self-reinforcing mesh is useful here: cleanup has to account for the routes that execute and restore the payload, not just the most visible file.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How to approach cleanup without triggering reinfection

Sucuri’s order is important: stop the malicious code from executing safely, remove off-disk copies and persistence mechanisms, then remove the file-based components. This is specialist incident response, not a sufficient do-it-yourself checklist for an established compromise.

Rank #4
FIDO2 U2F Security Key Passkey Two-Factor Authentication (2FA) USB Key PIN+Touch (Non-Biometric) USB-A Type TrustKey T110
  • Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T110. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
  • Certified with the new FIDO2 standard, T110 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
  • Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
  • Fits USB-A port : Insert the T110 security key into the USB-A port of each service and log in conveniently with one touch
  • For the driver download and user guide, please visit TrustKey Solutions Home support page.
  1. Contain and preserve access. Coordinate with the host or an incident responder, preserve evidence needed to understand the entry point, and prevent further exposure where possible. Avoid deleting files at random while the site may still be executing them.
  2. Neutralize the prepend target before changing the directive. Identify the file targeted by the auto_prepend_file setting and make it safe before stripping the directive. PHP can cache the prepend value; careless removal may break requests or leave the malicious target in use.
  3. Remove off-disk payloads and control data. Check and clean the encoded database option and shared-memory segment, along with any related control data. On shared hosting, removing a System V shared-memory segment may require the host or its owner.
  4. Remove other persistence and access. Find and remove malicious scheduled tasks, audit database triggers, and remove hidden or unauthorized administrator accounts.
  5. Clean the file-based components. Remove loaders, fake-plugin copies, restore archives, malicious drop-ins and injected theme code. Verify the active theme and relevant configuration rather than assuming the first suspicious file was the only one.
  6. Rescan and monitor. Recheck the site and watch for recreated components. If they return, treat that as evidence that persistence or the original entry point remains; deleting the new copy again does not resolve the cause.
  7. Rotate credentials. After containment and cleanup, change WordPress administrator and other potentially exposed credentials, and review access for accounts that should not remain.

Reducing the chance of another compromise

For prevention, Barbosa recommends promptly patching WordPress and its components, using a web application firewall (WAF) to block exploit attempts and help stop beaconing, and regularly auditing database options, scheduled tasks, triggers and user accounts. These are recommendations in Sucuri’s incident report, not a guarantee against compromise or a comparative test of security products. Monitoring and prevention are not substitutes for removing an established persistence system.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.