Threat Intelligence

Self-Healing WordPress Backdoor Rebuilds Itself After Cleanup, Researchers Warn

The Hacker News · 2 Oct 2026
Key Takeaway If your WordPress site shows signs of compromise, engage a specialist to check files, database, cron jobs, and server memory together, since removing just one component may not stop the infection from returning.

Security researchers at Sucuri have identified a sophisticated WordPress backdoor, dubbed SC, that persists across at least eight separate locations on an infected site, including files, the database, and shared server memory. If one component is deleted, the others detect the change and restore it, creating what researchers describe as a 'self-healing mesh' with no single point of failure.

The malware hides itself from the WordPress admin screen, communicates with attackers using the Ethereum blockchain, creates a hidden administrator account, and can inject malicious JavaScript to target site visitors with skimmers or other malware. It also uses scheduled tasks (cron jobs) that run independently of visitor traffic, allowing it to quietly redeploy itself on a set schedule even after a cleanup attempt appears successful.

Because the backdoor's code is obfuscated and spread across multiple storage layers, including RAM-based shared memory that can survive file and database cleaning, removing it requires more than a standard plugin or file deletion. Site owners who suspect compromise should assume reinfection is likely unless every persistence mechanism is addressed at once.

WordPress security malware website compromise

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.