← All articles

WordPress SC backdoor rebuilds itself from files database and shared memory after cleanup

Sucuri detailed a WordPress compromise using a backdoor it codenamed SC, after SC_ markers in the injected content, which it describes as a self-healing mesh. The payload lives in at least eight places at once, spread across files, the database, and a shared-memory segment, and every location can rebuild all the others. Cleaning every file on disk lets the next page load restore the whole set from the database or shared memory, so there is no single point to remove. The malware carries no readable function names, using a substitution cipher to unscramble its code, and a .user.ini auto_prepend_file runs a loader before every PHP request.

Check
Treat infected WordPress sites as needing coordinated full cleanup across files, database, and runtime, and rebuild from a known-good backup where feasible.
Affected
WordPress sites hit by the SC backdoor cannot be cleaned piecemeal, since files, database entries, and shared memory each regenerate the removed components.
Fix
Take the site offline during cleanup, purge all eight component types together, rotate credentials and keys, restore from clean backups, and harden PHP auto_prepend_file.