SC WordPress backdoor rebuilds itself: cleanup order matters
Sucuri found the SC WordPress backdoor hiding in 8 files, the database and shared memory. Delete in the wrong order and it rewrites itself in seconds.
Sucuri published an analysis on September 30 of a WordPress backdoor that rebuilds itself while you clean it. Its team calls it "SC." During a cleanup, the same backdoor kept coming back within seconds of deletion. The reason: eight copies on disk, more copies off disk, and every copy can restore the others. If you run a WordPress or WooCommerce store, the lesson is not "delete faster." It is "delete in the right order."
What actually happened
Per Sucuri's write-up and The Hacker News:
- Eight file locations. A
.user.iniwith anauto_prepend_filedirective, a visible shim and a hidden dot-prefixed loader inwp-content, thedb.phpandadvanced-cache.phpdrop-ins, a block in the theme'sfunctions.php, and two copies of a fake plugin calledhyper-engine-kit(one inmu-plugins, one inplugins). - Three off-disk copies. A gzip-and-base64 payload in an options row, a System V shared-memory segment that survives file and database cleanup, and WP-Cron hooks with random names.
- A hidden admin. It writes an administrator straight into the users tables, hides it from the user list and counts, and logs in with forged cookies. No password needed.
- Blockchain command and control. It reads instructions from an Ethereum smart contract through a list of about twenty public RPC gateways. Block one, and the rest still answer.
- Checkout skimming. On e-commerce sites it injects front-end JavaScript to skim checkout data. Visitors see a normal site.
Sucuri did not give a count of infected sites. The entry point is the usual list: vulnerable plugins or themes, weak admin passwords, insecure uploads.
Why it matters for your business
A "clean" site can be dirty a minute later. Most quick cleanups delete the bad plugin and call it done. With SC, that deletion triggers a rewrite from advanced-cache.php, the database or shared memory. Sucuri's order: neutralize the prepend file, then wipe the database row, shared memory and cron hooks, then remove the hidden admin, and only then delete the files in one pass.
Shared hosting makes this harder. Purging a shared-memory segment or restarting PHP-FPM needs server access many budget hosts do not give you. Ask your host now, before you need it.
Your payment page is the target. A skimmer on checkout is a card-data incident, not a cosmetic one. Count your admins in the database, not in the dashboard. The dashboard is what the malware edits.
Key takeaways
- Sucuri's SC backdoor hides in 8 files plus the database, shared memory and WP-Cron
- Each copy restores the others, so deleting files first triggers a rewrite
- It creates a hidden admin and skims checkout pages on e-commerce sites
- Command and control runs through an Ethereum contract via ~20 public RPC gateways
- Clean off-disk copies first, then the admin, then all files in one pass
Running checkout on a plugin stack nobody audits? We build commerce sites with a small, known dependency list and server access you actually control. See how we build or talk to us about a migration.
Sources: Sucuri, The Hacker News.
- #wordpress
- #malware
- #sucuri
- #woocommerce
- #security
Tommy Rush — Founder, Rush Commerce
Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More
Get The Rush Report weekly — one email, zero fluff.
Keep reading
Zammad CVE-2026-102489 on CISA KEV: patch your helpdesk
CISA added two exploited Zammad flaws to KEV. Chained, they turn a hijacked session into root on your helpdesk server. Upgrade to Zammad 7.2.0 and check for compromise.
Read itIBM Bob goes self-hosted: an AI coding agent behind your firewall
IBM Bob, IBM's AI coding agent, now runs self-hosted, on-prem, and air-gapped with Nemotron or Poolside models. What it means for where your source code goes.
Read it