Security researchers have uncovered a persistent WordPress malware strain that uses Ethereum infrastructure for command-and-control communications, making infected websites unusually difficult to clean.
According to cybersecurity firm Sucuri, the malware, known as “SC,” operates as a self-healing system capable of rebuilding itself even after administrators remove parts of the infection. Copies of the malicious payload are distributed across WordPress plugins, themes, databases and server environments.
Sucuri researchers discovered the payload in at least eight locations at the same time. This redundancy eliminates a single point of failure, meaning removing one infected component may not be enough to secure a compromised WordPress website.
The malware also avoids relying on a conventional command-and-control server that security teams could identify and block. Instead, SC reportedly contains a list of roughly 20 public Ethereum RPC gateways.
Ethereum RPC infrastructure normally allows wallets, applications and other software to communicate with the Ethereum blockchain. SC exploits these legitimate services for malicious communications. If one RPC provider becomes inaccessible, the malware can switch to another gateway, improving the attackers’ resilience against attempts to disrupt their operations.
The threat also gathers detailed information about compromised websites, including URLs, hostnames, WordPress versions and installed plugin versions. More seriously, SC can steal administrator session tokens, potentially allowing attackers to retain privileged access.
Attackers can then inject malicious JavaScript into a website’s front end. On e-commerce sites, such injections could potentially be used to capture payment information entered by customers during checkout.
Sucuri also found that the WordPress malware can disable security software and maintain administrator-level access, further complicating remediation efforts.
The malware’s distributed design means website owners may need to identify and eliminate every surviving component. If even one functional copy remains hidden within the compromised environment, SC may be capable of reconstructing the infection and restoring malicious access.
The discovery highlights how cybercriminals can abuse decentralized blockchain infrastructure such as Ethereum RPC gateways to make malware operations harder to disrupt.


DogeOS Launches Testnet to Bring DeFi Apps to Dogecoin
Apple CEO John Ternus Plans Major Overhaul
XRP Ledger Hits 10 Million AI Payments as Bitcoin Retreats
Citi Raises Bitcoin Target to $113,000 as Crypto Outlook Improves
Evernorth Set for Nasdaq Debut With 473 Million XRP Treasury
TRUMP Memecoin Launches New Dinner Contest
Michael Saylor Sees Strategy, Strive Expanding Bitcoin Credit Market
Lynas Shares Slide on A$968 Million Meteoric Resources Deal
Ripple and Cardano Expand Blockchain Adoption in Brazil
Robinhood Chain Meme Coins Slide as Stock Token Locks Rise
Apple iPhone 18 Pro Sales Jump 12% in China
OpenAI Investigates Rogue AI Agents After Data Leaks and Security Incidents
Petrobras Launches Cardano Apps to Track Low-Carbon Fuels
OpenAI AI Agents Bypassed UN Website Controls in Data Scraping
DeepSeek, Huawei Partner on Ascend AI Chip Programming Tools
Bitcoin Holds Above $83,700 as High Treasury Yields Limit Rally
Robinhood Stock Nears $114 as Jobs Data Boosts Risk Appetite 



