A newly identified WordPress malware strain tracked as SC is using Ethereum’s decentralized infrastructure to keep its command-and-control channels online, according to a warning from cybersecurity firm Sucuri. The malware is designed to be unusually persistent: it stores redundant copies of itself in at least eight system locations, including files, the WordPress database, and, where supported, System V shared memory. Any surviving copy can rebuild the infection if administrators remove only part of the compromised installation.
Unlike traditional attacks that rely on centralized command servers, the SC malware embeds a list of approximately 20 public Ethereum RPC gateways. By routing commands through Ethereum’s distributed network, the operators reduce the risk that their infrastructure will be seized or blocked. Sucuri said the campaign has been used to steal administrative session tokens, disable security defenses, and inject malicious JavaScript to exfiltrate payment credentials from digital storefronts.
The finding highlights a growing trend of threat actors repurposing Web3 architecture against legacy web platforms. Security experts recommend database-level audits, full replacement of compromised core files, and strict monitoring of outbound calls to blockchain nodes to detect and disrupt the reinfection loop.