Back to all news
Security

WordPress Backdoor Rebuilds Itself After Cleanup Using Files, Database, and Shared Memory

The Hacker News·October 1, 2026·1 min read
WordPress Backdoor Rebuilds Itself After Cleanup Using Files, Database, and Shared Memory

Cybersecurity researchers detailed a WordPress compromise where threat actors used multiple persistence mechanisms to ensure a backdoor, codenamed SC after "SC_" markers, kept returning after cleanup. The malware, described by Sucuri as a "self-healing mesh", hides in files, the database, and shared memory, allowing it to rebuild itself without reinfecting the site. Site owners face repeated reinfections until all traces are removed.

Read at The Hacker News
Daily crypto arcade

Read the news, then play it.

Chainshorts turns crypto headlines into a daily game. Catch up in 60 words, then jump into daily lucky draws for a shot at the pot.

Open ChainshortsGet it on the Solana dApp Store