Self-Healing WordPress Backdoor Rebuilds Itself After Cleanup, Researchers Warn
Security researchers at Sucuri have identified a sophisticated WordPress backdoor, dubbed SC, that persists across at least eight separate locations on an infected site, including files, the database, and shared server memory. If one component is deleted, the others detect the change and restore it, creating what researchers describe as a 'self-healing mesh' with no single point of failure.
The malware hides itself from the WordPress admin screen, communicates with attackers using the Ethereum blockchain, creates a hidden administrator account, and can inject malicious JavaScript to target site visitors with skimmers or other malware. It also uses scheduled tasks (cron jobs) that run independently of visitor traffic, allowing it to quietly redeploy itself on a set schedule even after a cleanup attempt appears successful.
Because the backdoor's code is obfuscated and spread across multiple storage layers, including RAM-based shared memory that can survive file and database cleaning, removing it requires more than a standard plugin or file deletion. Site owners who suspect compromise should assume reinfection is likely unless every persistence mechanism is addressed at once.