Recommended Free Tools
SC is a WordPress malware family that Sucuri documented in a September 2026 cleanup case. It kept returning because its payload was spread across files, WordPress locations, the database and shared memory, allowing surviving parts to rebuild removed ones. Its use of public Ethereum RPC gateways was a command channel—not evidence that Ethereum itself was compromised.
What is SC WordPress malware?
SC is the label Sucuri uses for the malware in its examined case, named for “SC_” markers found in injected content. Security analyst Gabriel Barbosa published the case analysis on September 30, 2026, after encountering a backdoor that reappeared seconds after cleanup attempts. That rapid return was a sign that deleting visible files had not removed every source capable of restoring them.
As an Amazon Associate I earn from qualifying purchases.
Sucuri describes the infection as a mutually reinforcing persistence system, rather than one malicious file. Barbosa put the distinction plainly: “SC is a reminder that a modern WordPress infection can be a system rather than a file.” Read Sucuri’s case analysis.
Why could the malware survive file cleanup?
In the compromise Sucuri analyzed, payload copies appeared in at least eight locations across files, WordPress, the database and shared memory. That is a finding about this case, not a fixed design for every SC infection or a measure of how common it is.
#1 Best Overall
- Configuration and loader files: A
.user.inidirective could use PHP’sauto_prepend_filesetting to load malicious code before ordinary PHP requests. Loader or shim files could serve as the target. - WordPress drop-ins and theme code: Sucuri found malicious code in drop-ins such as
wp-content/db.phpandadvanced-cache.php, as well as a block inserted into the active theme’sfunctions.php. - Duplicate fake plugins: Matching payloads appeared in both
mu-pluginsand the regularpluginsdirectory. Removing one copy could leave another. - Off-disk storage: An encoded payload in a database option and a System V shared-memory segment provided copies outside the visible plugin and theme files.
- Other persistence in related variants: Sucuri also describes scheduled tasks and database triggers. Their presence should be checked, but the report does not establish that every infected site had each mechanism.
File names can vary between sites. The practical consequence is that a surviving loader, task or off-disk copy may recreate a component that was just removed.
What does the Ethereum connection do?
The analyzed payload carried roughly twenty public Ethereum RPC gateways and selectors for querying smart-contract instructions. RPC gateways are services that let software read blockchain data; the malware used them to retrieve commands. This is abuse of legitimate infrastructure as a resilient command channel, not an attack on Ethereum itself. Sucuri’s reported gateway count describes the analyzed payload, not compromised networks.
Using many gateways means blocking a single observed endpoint may not stop the malware from receiving instructions through another. The report says the payload could receive front-end JavaScript or PHP, fingerprint the WordPress environment, gather details such as site versions, paths and administrator session tokens, and send encrypted data.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →What could the backdoor do on an infected site?
Sucuri reports capabilities that include creating or hiding privileged administrator accounts, deactivating and deleting security plugins, and injecting JavaScript into the site’s front end. These capabilities create risks; the case report does not establish that every infected site experienced every outcome.
For an online store, injected checkout JavaScript could capture payment information. That is a possible consequence if checkout code is targeted, not proof that payment theft occurred on every affected store. The report does not establish universal payment skimming.
What signs should a site owner investigate?
Sucuri’s indicators are clues from this malware case, not a complete signature for all WordPress compromises. An unfamiliar file or account is not conclusive by itself, but these findings warrant investigation:
Rank #4
- Unexpected SC-style code in
wp-content/db.phporadvanced-cache.php. - A suspicious block in the active theme’s
functions.php, or an unexpectedauto_prepend_filedirective in.user.ini. - A plugin that appears to be a fake or unfamiliar copy in both the normal and must-use plugin directories.
- Randomly named ZIP archives that appear to be restore bundles.
- A large, encoded value in the WordPress options table that the site owner cannot account for.
- An unexpected PHP-related System V shared-memory segment.
- Hidden or otherwise suspicious administrator accounts, or outbound web-server connections to public Ethereum RPC gateways.
Because a persistent infection can recreate removed files, finding one indicator should prompt an investigation of execution paths and other storage locations—not just deletion of the item found.
Free tools Windows power users keep installed
One-click scans. No signup required.
How should a returning infection be cleaned up?
Sucuri’s sequence prioritizes stopping execution safely, then removing off-disk persistence and control mechanisms before cleaning the file-based components. This is specialist incident response, not a guarantee that a partial checklist will disinfect a site. Preserve evidence if needed for an investigation, and involve a qualified incident responder or hosting provider when the site’s configuration or shared-memory access is outside your control.
Best Value
- Contain access and stop malicious execution safely. Work with the host or responder to neutralize the file targeted by
auto_prepend_filebefore stripping the directive. Sucuri warns that PHP may cache the prepend value; careless removal can break requests or leave execution active. - Remove off-disk payloads and control data. Inspect and clean the database option containing encoded data and remove the malicious shared-memory segment. On shared hosting, the provider or account owner may need to remove that segment.
- Audit persistence mechanisms. Find and remove malicious scheduled tasks, and inspect database triggers for related persistence or control logic.
- Remove unauthorized access. Identify and remove hidden or suspicious privileged accounts, then secure legitimate administrator access.
- Clean the file-based components. Remove malicious loaders, duplicate fake plugins, restore archives, infected drop-ins and the injected theme block. Make sure cleanup covers every affected copy and execution path.
- Rescan and watch for recurrence. Check whether any component is recreated after cleanup. Sucuri advises treating a return as evidence that persistence or the original entry point remains; continue investigating rather than repeatedly deleting the newly restored file.
- Rotate credentials. Once the infection is contained and access is secured, change credentials that could have been exposed, including WordPress administrator and relevant hosting or database credentials.
How can site owners reduce the risk?
For prevention, Sucuri recommends prompt patching, a web application firewall (WAF) to block exploit attempts and help stop beaconing, and regular audits of WordPress options, scheduled tasks, database triggers and user accounts. These are recommendations in its incident report, not a guarantee against compromise or a comparison of security products. A scanner or security plugin can help with monitoring, but it is not a substitute for removing an established persistence system.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




