Sucuri: WordPress Malware Relies on 20 Ethereum (ETH) RPC Gateways to Survive Cleanup
Security firm Sucuri says the SC WordPress malware hides in eight site layers and uses about 20 public Ethereum (ETH) RPC gateways to survive cleanup.
AI SummaryAI
- Sucuri identified the SC WordPress malware using Ethereum infrastructure for command-and-control on 2026-10-01.
- SC hides its payload in at least eight locations, including plugins, themes and the database.
- The malware carries a list of roughly 20 public Ethereum RPC gateways for fallback communication.
- SC steals administrator session tokens and injects JavaScript into compromised site front ends.
Malware That Rebuilds Itself
Security researchers at Sucuri have identified an unusually durable WordPress malware strain, tracked under the name SC, that abuses
Ethereum (ETH) infrastructure for its command-and-control communications. The firm's public security advisory, published on Thursday 2026-10-01, describes a self-healing implant that survives cleanup by scattering redundant copies of its payload across every layer of a compromised website. Forensic analysis of infected sites showed the malicious code present in at least eight distinct locations simultaneously, spanning WordPress plugins, themes, the site database and supported server components. Sucuri's team reached the conclusion after investigating compromised WordPress installations. That design removes any single point of failure. As long as one sufficiently capable piece of the mesh stays alive, SC can rebuild itself and reappear soon after an incomplete removal attempt. Routine WordPress infections usually hide in one file or one service, so cleaning that component ends the incident. Here, a partial cleanup effectively guarantees re-infection, which is why the removal process is rated as markedly harder than in ordinary cases. The report frames the discovery as evidence that attacks on the WordPress ecosystem are pushing deeper into the infrastructure layer, where several cooperating components must be neutralized in one pass before a site can be called clean. A second layer of the story concerns the
Ethereum (ETH) ecosystem directly. SC does not operate its own command servers at all. Instead it carries a rotating list of public blockchain endpoints and treats them as free, resilient channels that anyone can reach but no single defender can take away. The same open access layer that serves the wider altcoin ecosystem has been repurposed as a lifeline for malware, and switching providers on that list takes the attackers seconds rather than days.
Roughly 20 Public RPC Gateways
The resilience of the campaign rests on how SC talks to its operators. A conventional command-and-control server can be knocked out with a single block, but SC ships with a list of roughly 20 public Ethereum RPC gateways. RPC endpoints are the technical access points through which applications and crypto wallets send and receive data on the blockchain, and they are operated as open services by default. When a defender blocks one gateway, the malware simply moves to another provider on its list, a fallback behavior that makes the operation far harder to strangle than a traditional botnet channel. If one endpoint is filtered, the traffic simply reappears through another. Sucuri's analysis is explicit on scope: the abuse does not reach the chain itself. Validators, block production and on-chain funds sit outside the blast radius; what is being hijacked is the access layer in front of the network. Legitimate blockchain infrastructure is being misused for malicious purposes. The forensic detail collected from compromised sites included URLs, hostnames, the installed WordPress version and plugin versions, a fingerprinting pass that helps operators adapt to each host. The more serious capability is credential theft. SC can harvest administrator session tokens, and with that access it injects JavaScript into the site's front end. On e-commerce stores, that injection can turn the checkout step into a skimmer that collects payment details, a risk for merchants rather than for spot trading venues. The implant can also disable security tooling and preserve administrator-level access inside WordPress, so an attacker who gets in once can keep the door open.
Access Layer, Not the Chain
Read together, the findings describe a shift from file-level infection to infrastructure-level persistence. In COINOTAG's view, the advisory works best as an operational checklist: sweep plugins, themes, the database and server components in a single pass, rotate administrator credentials, and audit outbound connections to public RPC providers. The finding is a technical fact about open endpoints, not FUD aimed at the network, and Ethereum price action sits entirely outside this incident. For desks tracking Ethereum network infrastructure, the episode lands alongside other stress points this year, from MetaMask's validator exit to the
Ethereum (ETH) Foundation's ZKAPI launch.
AI-generated, AI-reviewed, under COINOTAG editorial oversight.

