
Security researchers have uncovered a highly complex WordPress compromise involving a self-healing, blockchain-controlled backdoor codenamed “SC”. Discovered by Sucuri, the malware deploys multiple interconnected persistence mechanisms across a server to ensure the payload continually regenerates if removed.
An Eight-Component Self-Healing Mesh
According to Sucuri, the backdoor uses a substitution cipher to decode its functions and spreads identical copies of its payload across at least eight distinct locations, including files, the database, and shared memory. Security researcher Gabriel Barbosa noted that the system creates a circular loop with no single point of failure:
- .user.ini: Sets
auto_prepend_fileto execute a loader prior to every PHP request in the directory tree. - wp-content/c1b12371.php: A loader file designed to include a hidden dot-prefixed file if present in the same location.
- wp-content/.c1b12371.php: A hidden first-stage loader that locates a fake plugin and rebuilds it inside
mu-pluginsusing local files, cache stubs, or a ZIP restore bundle. - wp-content/db.php: Loaded during bootstrap, carrying the full backdoor payload in a compressed, Base64-encoded format to re-deploy missing plugins.
- wp-content/advanced-cache.php: Loaded prior to ordinary plugins when caching is enabled, rebuilding the plugin from five independent sources including shared memory and the database.
- wp-content/themes/khorshidi/functions.php: A theme-resident twin of the backdoor payload that rewrites the plugin if it is missing.
- wp-content/mu-plugins/hyper-engine-kit.php: The core malware installed as both a must-use and normal plugin.
- wp-content/plugins/hyper-engine-kit/hyper-engine-kit.php: A redundant duplicate of the backdoor payload.
Furthermore, on servers supporting System V shared memory, the payload resides in a RAM segment identified by a fixed numeric key, allowing it to survive file and database cleanups. The malware also registers cron hooks to automate redeployment and communicates with its command-and-control (C2) server via the Ethereum blockchain to fetch additional payloads, inject JavaScript skimmers, create hidden administrator accounts, and execute arbitrary PHP code.
Active Exploitation of wpForo Forum Plugin Flaw
Concurrent with the disclosure of the SC malware, telemetry data from Previdian has revealed active exploitation of a high-severity unauthenticated SQL injection vulnerability in the wpForo Forum WordPress plugin. Tracked as CVE-2026-1581 with a CVSS score of 7.5, the flaw affects all versions up to and including 2.4.14. Fewer than 20 exploitation attempts have been tracked since July 3, 2026, originating from IP addresses in Bulgaria, Switzerland, France, the U.S., and Yemen.