Skip to content
Rush Commerce
Software & Dev3 min read

SC WordPress backdoor rebuilds itself: cleanup order matters

Sucuri found the SC WordPress backdoor hiding in 8 files, the database and shared memory. Delete in the wrong order and it rewrites itself in seconds.

Sucuri published an analysis on September 30 of a WordPress backdoor that rebuilds itself while you clean it. Its team calls it "SC." During a cleanup, the same backdoor kept coming back within seconds of deletion. The reason: eight copies on disk, more copies off disk, and every copy can restore the others. If you run a WordPress or WooCommerce store, the lesson is not "delete faster." It is "delete in the right order."

What actually happened

Per Sucuri's write-up and The Hacker News:

  • Eight file locations. A .user.ini with an auto_prepend_file directive, a visible shim and a hidden dot-prefixed loader in wp-content, the db.php and advanced-cache.php drop-ins, a block in the theme's functions.php, and two copies of a fake plugin called hyper-engine-kit (one in mu-plugins, one in plugins).
  • Three off-disk copies. A gzip-and-base64 payload in an options row, a System V shared-memory segment that survives file and database cleanup, and WP-Cron hooks with random names.
  • A hidden admin. It writes an administrator straight into the users tables, hides it from the user list and counts, and logs in with forged cookies. No password needed.
  • Blockchain command and control. It reads instructions from an Ethereum smart contract through a list of about twenty public RPC gateways. Block one, and the rest still answer.
  • Checkout skimming. On e-commerce sites it injects front-end JavaScript to skim checkout data. Visitors see a normal site.

Sucuri did not give a count of infected sites. The entry point is the usual list: vulnerable plugins or themes, weak admin passwords, insecure uploads.

Why it matters for your business

A "clean" site can be dirty a minute later. Most quick cleanups delete the bad plugin and call it done. With SC, that deletion triggers a rewrite from advanced-cache.php, the database or shared memory. Sucuri's order: neutralize the prepend file, then wipe the database row, shared memory and cron hooks, then remove the hidden admin, and only then delete the files in one pass.

Shared hosting makes this harder. Purging a shared-memory segment or restarting PHP-FPM needs server access many budget hosts do not give you. Ask your host now, before you need it.

Your payment page is the target. A skimmer on checkout is a card-data incident, not a cosmetic one. Count your admins in the database, not in the dashboard. The dashboard is what the malware edits.

Key takeaways

  • Sucuri's SC backdoor hides in 8 files plus the database, shared memory and WP-Cron
  • Each copy restores the others, so deleting files first triggers a rewrite
  • It creates a hidden admin and skims checkout pages on e-commerce sites
  • Command and control runs through an Ethereum contract via ~20 public RPC gateways
  • Clean off-disk copies first, then the admin, then all files in one pass

Running checkout on a plugin stack nobody audits? We build commerce sites with a small, known dependency list and server access you actually control. See how we build or talk to us about a migration.

Sources: Sucuri, The Hacker News.

  • #wordpress
  • #malware
  • #sucuri
  • #woocommerce
  • #security
TR

Tommy Rush — Founder, Rush Commerce

Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More

Get The Rush Report weekly — one email, zero fluff.