WordPress Backdoor Rebuilds Itself After Cleanup Using Files, Database, and Shared Memory

Executive Summary

Researchers uncovered a WordPress backdoor that self‑heals after cleanup by re‑injecting code via files, database entries, and shared memory. The malware, codenamed SC due to SC_ markers, uses multiple persistence mechanisms so the final payload returns without re‑infection. Sucuri calls it a “self‑healing mesh.”


Intelligence Metadata - Source Publisher: The Hacker News - Published Date: 2026-10-01T14:37:35+00:00 - Category: threat-intel

Original Description: Cybersecurity researchers have shed light on a WordPress compromise in which threat actors deployed multiple persistence mechanisms to ensure that the final payload kept returning without having to infect the site again. The backdoor has been codenamed SC after the "SC_" markers present in the injected content. Sucuri has described the malware as a "self-healing mesh" that's

"A rolling stone gathers no moss."

— Publilius Syrus
Source: The Hacker News