BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
Altcoins

WordPress malware uses Ethereum RPC for self-healing attacks, Sucuri warns

Security company Sucuri has reported the discovery of a persistent malware variant targeting WordPress sites, which leverages the Ethereum blockchain’s infrastructure as part of its command-a

AnonymousCryptoCompass newsroom
October 1, 2026
3 min read
NEWS
Hero article visual / chart / editorial image
CryptoCompass editorial visual for altcoins coverage.

Security company Sucuri has reported the discovery of a persistent malware variant targeting WordPress sites, which leverages the Ethereum blockchain’s infrastructure as part of its command-and-control operations.

Ethereum-powered command and control

This malware, referred to as “SC” by Sucuri, has been described as a “self-healing” threat. Instead of relying on a traditional centralized command-and-control server, the malware utilizes a list of roughly 20 public Ethereum Remote Procedure Call (RPC) gateways to receive instructions. By distributing control mechanisms across several decentralized gateways, rather than a single server, attackers ensure there is no single point of failure.

Should a gateway be blocked or removed, the malware seamlessly switches to another available Ethereum RPC provider. This use of legitimate blockchain infrastructure, which typically allows applications, wallets, and services to access the Ethereum network, gives attackers enhanced resilience and flexibility.

Mini dictionary: Ethereum RPC Gateway, a public interface that allows software to access and interact with blockchain data on the Ethereum network without running a full node.

Traditional C2 Method “SC” Malware Approach Single central server used for commands Roughly 20 public Ethereum RPC gateways leveraged Easier to block by defenders No single point of failure, switching between gateways Not blockchain-based Uses legitimate blockchain infrastructure

Persistence and infection method

SC malware maintains resilience by hiding copies of its malicious payload in multiple places, including WordPress plugins, themes, the database, and the server environment. Sucuri identified the malware simultaneously in at least eight separate locations across infected systems. This redundancy allows the malware to regenerate itself even after partial removal attempts, making full eradication significantly more complex for administrators.

Sucuri highlighted the danger of the malware’s design. The distributed storage of its components and the use of decentralized infrastructure mean that standard remediation efforts are often insufficient if even a single malware variant survives.

Capabilities and risks

The SC malware collects details from compromised websites, including URLs, hostnames, WordPress version information, and plugin versions. Notably, it can also steal administrator session tokens, giving attackers prolonged privileged access.

Attackers may use their access to inject JavaScript into a site’s front end. This enables various malicious actions, such as skimming payment card details from e-commerce transactions during user checkout processes.

SC can also deactivate a range of security software and maintain administrator-level access within WordPress, making disinfection attempts even more difficult.

Given this malware’s architectural resilience, Sucuri stressed that the recovery process for affected websites is challenging. Even if a lone undetected instance of the payload remains, it can quickly restore the malware across the system.

The post WordPress malware uses Ethereum RPC for self-healing attacks, Sucuri warns appeared first on COINTURK NEWS.