WordPress SC Backdoor Rebuilds Itself After Cleanup Using Files Database and Shared Memory
Sucuri found a WordPress backdoor that hides in at least eight places across files, the database and server RAM, so deleting one copy just triggers the others to restore it.

Cleaning a hacked WordPress site usually means finding the bad files and deleting them. A newly documented backdoor makes that approach useless. Sucuri researcher Gabriel Barbosa detailed malware that lives in at least eight places at once across a site's files, its database and the server's shared memory, and every copy can rebuild the others.
The researchers codenamed it SC, after the "SC_" markers it leaves in injected content. The practical effect is grim for anyone doing incident response by hand: delete the plugin and a drop-in rewrites it, delete the drop-in and the theme rewrites it, wipe every file on disk and the next page load restores the whole set from the database or from RAM.
A mesh, not a single file
SC is built as a self-healing mesh. Its pieces start with a .user.ini file that sets PHP's auto_prepend_file directive, so a loader runs before WordPress itself on every request. More loaders sit under wp-content, including a hidden file whose name starts with a dot.
The attackers also abuse two legitimate WordPress drop-ins, db.php and advanced-cache.php, which carry a compressed Base64 payload. A twin copy lives in the active theme's functions.php. On top of that, a fake plugin called hyper-engine-kit is installed twice, once as a must-use plugin and once as a normal plugin.
Cron hooks with randomized names keep the redeployment on schedule, and the code is obfuscated with a substitution cipher and stripped of readable function names, which makes manual review painful.
The copy that survives in RAM
The most unusual piece is the one that never touches disk. On servers that support System V shared memory, SC writes its payload into a memory segment with a fixed numeric key. That segment lives in RAM, so it can outlast file deletion and a database cleanup alike.
On shared hosting the problem gets stranger. The memory segment can end up owned by a different account on the same server, which means the site owner may not even have the permissions to see or remove it.
What the payload does once it is in
SC is not just persistent, it is capable. According to the researchers, it hides itself from the admin plugins screen and from update checks, so a site owner browsing the dashboard sees nothing unusual.
It reaches its command and control infrastructure through the Ethereum blockchain, a technique that makes takedowns harder because there is no single domain to seize. It fingerprints the infected site, creates a hidden administrator account, and can inject JavaScript skimmers aimed at visitors. Operators can also run arbitrary PHP and deactivate or delete other plugins, including security tools.
That combination turns a compromised site into a platform for stealing payment data or credentials from the people who visit it.
Nobody knows how it gets in
The initial infection path is still unknown. The usual suspects for WordPress compromises are vulnerable plugins or themes, weak admin credentials, supply chain attacks and insecure file uploads. This year has had no shortage of the first category, from a one-click admin flaw that led to remote code execution to a site takeover bug in All-in-One WP Migration.
There is no evidence that SC is spreading across WordPress at large, and the researchers have not attributed it to a known group. What it shows is how far attackers will go to keep access once they have it.
For defenders, the lesson is that cleanup has to be simultaneous. Files, drop-ins, the theme, must-use plugins, the database, cron entries, hidden admin users and shared memory all need to be cleared in the same pass, with the shared memory segment removed or the server rebooted, and fresh credentials issued. Miss one piece and the rest come back on the next page load.
The same week brought another reminder that WordPress plugins remain a soft target: attackers are actively exploiting a SQL injection flaw in the wpForo Forum plugin, tracked as CVE-2026-1581 with a CVSS score of 7.5, though only a small number of attempts have been seen since July 3.
Cyberpresso: daily cyber & AI brief
Free daily newsletter, read in 5 minutes.
Subscribe free