Driver FixRecommendedSound, Wi-Fi or graphics acting up? Check drivers firstFind missing or outdated drivers fast.Check DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsWindows FixRecommendedWindows errors stealing your time? Find the fix fastScan stability, cleanup and performance issues.Fix Now×
Skip to content
World desk5 min

Why SC WordPress Malware Keeps Returning After Cleanup

Sucuri’s SC malware case shows why deleting visible WordPress files may not stop reinfection—and what a thorough response needs to address.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

SC is a WordPress malware family that Sucuri documented in a September 2026 cleanup case. It kept returning because its payload was spread across files, WordPress locations, the database and shared memory, allowing surviving parts to rebuild removed ones. Its use of public Ethereum RPC gateways was a command channel—not evidence that Ethereum itself was compromised.

What is SC WordPress malware?

SC is the label Sucuri uses for the malware in its examined case, named for “SC_” markers found in injected content. Security analyst Gabriel Barbosa published the case analysis on September 30, 2026, after encountering a backdoor that reappeared seconds after cleanup attempts. That rapid return was a sign that deleting visible files had not removed every source capable of restoring them.

As an Amazon Associate I earn from qualifying purchases.

Sucuri describes the infection as a mutually reinforcing persistence system, rather than one malicious file. Barbosa put the distinction plainly: “SC is a reminder that a modern WordPress infection can be a system rather than a file.” Read Sucuri’s case analysis.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Why could the malware survive file cleanup?

In the compromise Sucuri analyzed, payload copies appeared in at least eight locations across files, WordPress, the database and shared memory. That is a finding about this case, not a fixed design for every SC infection or a measure of how common it is.

  • Configuration and loader files: A .user.ini directive could use PHP’s auto_prepend_file setting to load malicious code before ordinary PHP requests. Loader or shim files could serve as the target.
  • WordPress drop-ins and theme code: Sucuri found malicious code in drop-ins such as wp-content/db.php and advanced-cache.php, as well as a block inserted into the active theme’s functions.php.
  • Duplicate fake plugins: Matching payloads appeared in both mu-plugins and the regular plugins directory. Removing one copy could leave another.
  • Off-disk storage: An encoded payload in a database option and a System V shared-memory segment provided copies outside the visible plugin and theme files.
  • Other persistence in related variants: Sucuri also describes scheduled tasks and database triggers. Their presence should be checked, but the report does not establish that every infected site had each mechanism.

File names can vary between sites. The practical consequence is that a surviving loader, task or off-disk copy may recreate a component that was just removed.

What does the Ethereum connection do?

The analyzed payload carried roughly twenty public Ethereum RPC gateways and selectors for querying smart-contract instructions. RPC gateways are services that let software read blockchain data; the malware used them to retrieve commands. This is abuse of legitimate infrastructure as a resilient command channel, not an attack on Ethereum itself. Sucuri’s reported gateway count describes the analyzed payload, not compromised networks.

Using many gateways means blocking a single observed endpoint may not stop the malware from receiving instructions through another. The report says the payload could receive front-end JavaScript or PHP, fingerprint the WordPress environment, gather details such as site versions, paths and administrator session tokens, and send encrypted data.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What could the backdoor do on an infected site?

Sucuri reports capabilities that include creating or hiding privileged administrator accounts, deactivating and deleting security plugins, and injecting JavaScript into the site’s front end. These capabilities create risks; the case report does not establish that every infected site experienced every outcome.

For an online store, injected checkout JavaScript could capture payment information. That is a possible consequence if checkout code is targeted, not proof that payment theft occurred on every affected store. The report does not establish universal payment skimming.

What signs should a site owner investigate?

Sucuri’s indicators are clues from this malware case, not a complete signature for all WordPress compromises. An unfamiliar file or account is not conclusive by itself, but these findings warrant investigation:

  • Unexpected SC-style code in wp-content/db.php or advanced-cache.php.
  • A suspicious block in the active theme’s functions.php, or an unexpected auto_prepend_file directive in .user.ini.
  • A plugin that appears to be a fake or unfamiliar copy in both the normal and must-use plugin directories.
  • Randomly named ZIP archives that appear to be restore bundles.
  • A large, encoded value in the WordPress options table that the site owner cannot account for.
  • An unexpected PHP-related System V shared-memory segment.
  • Hidden or otherwise suspicious administrator accounts, or outbound web-server connections to public Ethereum RPC gateways.

Because a persistent infection can recreate removed files, finding one indicator should prompt an investigation of execution paths and other storage locations—not just deletion of the item found.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How should a returning infection be cleaned up?

Sucuri’s sequence prioritizes stopping execution safely, then removing off-disk persistence and control mechanisms before cleaning the file-based components. This is specialist incident response, not a guarantee that a partial checklist will disinfect a site. Preserve evidence if needed for an investigation, and involve a qualified incident responder or hosting provider when the site’s configuration or shared-memory access is outside your control.

  1. Contain access and stop malicious execution safely. Work with the host or responder to neutralize the file targeted by auto_prepend_file before stripping the directive. Sucuri warns that PHP may cache the prepend value; careless removal can break requests or leave execution active.
  2. Remove off-disk payloads and control data. Inspect and clean the database option containing encoded data and remove the malicious shared-memory segment. On shared hosting, the provider or account owner may need to remove that segment.
  3. Audit persistence mechanisms. Find and remove malicious scheduled tasks, and inspect database triggers for related persistence or control logic.
  4. Remove unauthorized access. Identify and remove hidden or suspicious privileged accounts, then secure legitimate administrator access.
  5. Clean the file-based components. Remove malicious loaders, duplicate fake plugins, restore archives, infected drop-ins and the injected theme block. Make sure cleanup covers every affected copy and execution path.
  6. Rescan and watch for recurrence. Check whether any component is recreated after cleanup. Sucuri advises treating a return as evidence that persistence or the original entry point remains; continue investigating rather than repeatedly deleting the newly restored file.
  7. Rotate credentials. Once the infection is contained and access is secured, change credentials that could have been exposed, including WordPress administrator and relevant hosting or database credentials.

How can site owners reduce the risk?

For prevention, Sucuri recommends prompt patching, a web application firewall (WAF) to block exploit attempts and help stop beaconing, and regular audits of WordPress options, scheduled tasks, database triggers and user accounts. These are recommendations in its incident report, not a guarantee against compromise or a comparison of security products. A scanner or security plugin can help with monitoring, but it is not a substitute for removing an established persistence system.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. World desk4 min
    How to Spot an AI Voice Scam Before Sending MoneyDon’t rely on how a caller sounds. Pause, call back through a known number, and verify the emergency with another trusted person before sending money.
  2. Mountain View desk4 min
    Google’s SynthID Detector: How to Check AI-Generated Images, Video and AudioGoogle’s SynthID Detector looks for an embedded watermark in supported images, video and audio. Here is what its results do—and do not—show.
  3. Redmond desk20 min
    How to create a link to File or Folder in Windows 11Windows 11 gives you several ways to point to a file or folder without moving or duplicating it. You can create a desktop shortcut,…
Recommended PC Tool
Recommended PC Tool
Crashes, No Sound, or Screen Glitches?Free driver scan
PC Slower Than It Used to Be?Free scan - under a minute

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.