Security researchers have uncovered a persistent WordPress malware strain that uses Ethereum infrastructure for command-and-control communications, making infected websites unusually difficult to clean.
According to cybersecurity firm Sucuri, the malware, known as “SC,” operates as a self-healing system capable of rebuilding itself even after administrators remove parts of the infection. Copies of the malicious payload are distributed across WordPress plugins, themes, databases and server environments.
Sucuri researchers discovered the payload in at least eight locations at the same time. This redundancy eliminates a single point of failure, meaning removing one infected component may not be enough to secure a compromised WordPress website.
The malware also avoids relying on a conventional command-and-control server that security teams could identify and block. Instead, SC reportedly contains a list of roughly 20 public Ethereum RPC gateways.
Ethereum RPC infrastructure normally allows wallets, applications and other software to communicate with the Ethereum blockchain. SC exploits these legitimate services for malicious communications. If one RPC provider becomes inaccessible, the malware can switch to another gateway, improving the attackers’ resilience against attempts to disrupt their operations.
The threat also gathers detailed information about compromised websites, including URLs, hostnames, WordPress versions and installed plugin versions. More seriously, SC can steal administrator session tokens, potentially allowing attackers to retain privileged access.
Attackers can then inject malicious JavaScript into a website’s front end. On e-commerce sites, such injections could potentially be used to capture payment information entered by customers during checkout.
Sucuri also found that the WordPress malware can disable security software and maintain administrator-level access, further complicating remediation efforts.
The malware’s distributed design means website owners may need to identify and eliminate every surviving component. If even one functional copy remains hidden within the compromised environment, SC may be capable of reconstructing the infection and restoring malicious access.
The discovery highlights how cybercriminals can abuse decentralized blockchain infrastructure such as Ethereum RPC gateways to make malware operations harder to disrupt.


Standard Chartered Sees Ethena ENA Hitting $2 by 2028
China Says U.S. Shares Responsibility for AI Governance
XRP Rises as Evernorth Merger Vote Clears Key Nasdaq Hurdle
Ethereum Price Eyes $3,000 as Fed Rate Hike Odds Drop
Vitalik Buterin Says Hegota Could Be Ethereum’s Last Conventional Fork
MSTR Stock Rises 3% as Strategy Challenges MSCI Bitcoin Stance
Samsung Invests $1 Billion in KKR’s Helix AI Infrastructure
Cardano Price Struggles as NIGHT Token Surges 20%
Circle Urges EU to Revise MiCA Stablecoin Rules
Citi Raises Bitcoin Target to $113,000 as Crypto Outlook Improves
Binance Pay Goes Live at PayPay Merchants in Japan
Pi Network Price Holds $0.087 as Protocol 28 Mainnet Upgrade Nears
Apple iPhone 18 Pro Sales Jump 12% in China 



