WordPress Compromise Unveils Self-Healing Malware
In a groundbreaking revelation, cybersecurity experts have uncovered a sophisticated vulnerability within WordPress, wherein malicious actors have employed a variety of persistence mechanisms to safeguard their final payload from being eradicated, ensuring its continuity without the need for repeated infections.
The malware, designated as SC due to the distinctive “SC_” markers in the intrusively injected content, has been characterized by Sucuri as a “self-healing mesh” controlled through blockchain technology.
Security researcher Gabriel Barbosa elucidated, “This payload exists concurrently in at least eight distinct locations—dispersed throughout files, the database, and shared memory.
Each location possesses the inherent capability to reconstruct all others.” Barbosa further remarked, Eliminate the plugin, and a drop-in recreates it. Erase the drop-in, and the theme replicates it.
Purge every file on the system, and upon the next page load, the entire configuration is restored either from the database or from a shared-memory segment. Consequently, it forms a circular system devoid of a singular point of removal to halt it.
As noted by Sucuri, the malware circumvents traditional identification methods by omitting any recognizable function names, instead integrating a decoder that unscrambles the code via a substitution cipher. An overview of the eight integral components is as follows:
- .user.ini: Configures “auto_prepend_file” to execute a loader before every PHP request in that hierarchical directory.
- wp-content/c1b12371.php: A loader that incorporates a hidden dot-prefixed file, contingent upon its presence in the corresponding location.
- wp-content/.c1b12371.php: This hidden dot-prefixed file serves as the initial-stage loader to identify a counterfeit plugin, reconstructing it in mu-plugins from three origins: an extant copy in the plugins directory, an encoded fragment in the cache, and a ZIP restoration package with a randomized hexadecimal name.
- wp-content/db.php: Engaged during the initial bootstrapping process, this file harbors the entirety of the backdoor payload in a compressed, Base64-encoded format. It ensures the plugin is decoded and redeployed whenever it is absent or inadequately sized.
- wp-content/advanced-cache.php: This file is activated by WordPress prior to standard plugins when caching is activated and reconstructs the plugin from five independent sources: an existing mu-plugin, an existing plugin copy, a System V shared-memory segment containing PHP, a ZIP bundle, and the database. It subsequently invokes plugins_loaded and incorporates it.
- wp-content/themes/khorshidi/functions.php: A theme-resident counterpart of db.php, which features the identical backdoor and replicates the plugin whenever it ceases to be present.
- wp-content/mu-plugins/hyper-engine-kit.php: The actual malware implanted as both a must-use plugin and a conventional plugin.
- wp-content/plugins/hyper-engine-kit/hyper-engine-kit.php: A duplicate of the same backdoor payload, introduced for redundancy.
The backdoor is equipped with an array of functionalities, enabling the operator to commandeer the WordPress site, retrieve arbitrary JavaScript for injection, target site visitors with skimming tools (or other malware), execute PHP code, and deactivate or eliminate specific plugins.
On systems supporting System V shared memory, Sucuri detailed how the payload is embedded within a segment marked by a fixed numeric key.
“This segment resides in RAM, thus persisting despite file deletions and database clearances; on shared hosting, it can even be controlled by a different account,” they explained.
The infection establishes cron hooks, incorporating randomized titles alongside a familiar fetch hook. The system cron activates the WordPress cron file independently of visitor traffic, subsequently initiating redeployment based on a predetermined schedule.
The precise method by which this malware infiltrated the WordPress site remains undetermined. Nevertheless, common initial access vulnerabilities encompass known exploits within WordPress, plugins, and themes; inadequate login credentials; software supply chain malignancies targeting widely-used plugins; and the exploitation of insecure media or form upload mechanisms to introduce PHP web shells into server directories.
“SC serves as a poignant reminder that contemporary WordPress infections may constitute a system rather than merely a file,” Sucuri asserted.
“This toolkit disseminates identical replicas of a singular backdoor across drop-ins, the theme, a counterfeit plugin in two locations, the database, and shared memory, concealing its command channel within legitimate blockchain infrastructure, and self-replicating from any surviving iteration at the very next request.”
Exploitation of wpForo Forum WordPress Plugin Vulnerability

The current discourse is accentuated by the discovery of a high-severity, unauthenticated SQL injection vulnerability in the wpForo Forum WordPress plugin (CVE-2026-1581, CVSS score: 7.5), which has recently come under active exploitation. This issue impacts all plugin versions up to and including 2.4.14.
Telemetry data sourced from Previdian indicates that fewer than 20 attempts to exploit this vulnerability have been documented since July 3, 2026.
The activity appears to emanate from five distinct attacker IP addresses located in Bulgaria, Switzerland, France, the United States, and Yemen.
Source link: Thehackernews.com.



