Malware uses Ethereum RPC to control and hide on WordPress
Malware "SC" targets WordPress, using Ethereum RPC gateways for control. It hides in multiple locations, self-heals, steals admin tokens, and injects malicious code, making removal very difficult.
A sophisticated malware strain known as "SC" is actively targeting WordPress sites by leveraging the Ethereum blockchain for its command-and-control operations. According to security firm Sucuri, this malware embeds itself across multiple layers of the WordPress ecosystem, including plugins, themes, databases, and servers. At least eight simultaneous infection points have been identified. SC features a self-healing mechanism, allowing it to regenerate from backup copies and making removal extremely challenging. Instead of relying on a single command-and-control server, SC cycles through a list of about 20 public Ethereum RPC gateways, switching if one is blocked. This decentralized approach removes single points of failure and increases the malware's resilience. The malware also collects site metadata, steals administrator session tokens, injects malicious JavaScript, and disables security plugins. These tactics complicate cleanup efforts and heighten the risk of data theft. SC's use of legitimate blockchain infrastructure for malicious purposes underscores a growing trend of cyberattacks exploiting decentralized technologies.