thehackernews.com 1 Oct 2026, 14:37 UTC

WordPress Backdoor Uses Self-Healing Mesh to Survive Cleanup

CyberSIXT Evidence Panel Source marked as original reporting
CISA KEV Not in KEV
Patch Patch Status Unknown

SECURITY researchers have disclosed a highly persistent WordPress infection that uses a “self-healing mesh” backdoor, codenamed SC, to ensure the final payload remains accessible even after apparent cleanup. The backdoor operates across eight locations simultaneously—in files, the database, and a System V shared memory segment—so that deleting one component or rewriting a single file does not disrupt the overall infection. Sucuri describes the system as capable of rebuilding all parts from any surviving source, creating a resilient, circular infection chain.

Evidence presented by Sucuri details multiple components that cooperate to restore the backdoor: a loader in .user[.]ini and in wp-content/c1b12371[.]php, a hidden dot-prefixed wp-content/.c1b12371[.]php loader, and payload delivery through wp-content/db[.]php, wp-content/advanced-cache[.]php, and theme/plugin equivalents. The payload is stored in compressed, Base64-encoded form, and the scheme utilises a hidden administrator account, anti‑cleanup measures, and a C2 channel that leverages the Ethereum blockchain.

The malware hides itself from the admin plugins screen and update checks, fingerprints the site, fetches additional payloads, and coordinates reinfection when components are missing or altered. It also asserts persistence through scheduled cron hooks and deploys identical backdoors across mu-plugins, themes, fake plugins, the database, and shared memory.

Among the stated impacts, the campaign can execute arbitrary JavaScript, inject site visitors with skimmers, run PHP code, and deactivate or delete plugins. The threat actor’s entry methods likely involve common WordPress attack vectors, including weak credentials and vulnerable plugins, though the article notes no single delivery vector is confirmed.

Separately, the report highlights a high‑severity unauthenticated SQL injection in wpForo (CVE-2026-1581, CVSS 7.5) with exploitation activity observed against versions up to 2.4.14.

View full article

Article by CyberSIXT