The WordPress backdoor that rebuilds itself. Deleting the files is not a cleanup

Every agency has had the call: the site was cleaned last week and the malware is back. Sucuri published a breakdown on September 30 of a family it calls SC — named after the `SC_` markers it leaves in injected code — and it explains that call better than anything we’ve read this year. The payload keeps itself in eight places at once, and every one of them can rebuild all the others. This is the scenario a maintenance retainer that covers malware cleanup and re-scanning is built around, because a one-off clean here genuinely does not hold.

Eight copies, one circle

Per Sucuri’s analysis, the infection lives in:

  • .user.ini setting `auto_prepend_file`, so a loader runs before WordPress does
  • A visible shim in wp-content (e.g. `c1b12371.php`) and a hidden dot-prefixed twin (`.c1b12371.php`)
  • wp-content/db.php and wp-content/advanced-cache.php — both drop-ins, both carrying the full payload gzip+base64 encoded
  • A bounded block appended to the active theme’s functions.php
  • A fake plugin deployed twice: once in mu-plugins and once in plugins

Delete the plugin, the drop-in rewrites it. Delete the drop-in, the theme rewrites it. Wipe every file on disk and the next page load pulls the payload back out of the database or out of a System V shared-memory segment. Cron hooks with randomised names redeploy it even on a site with no visitors.

The two places nobody checks

Two of those persistence points are why “I removed the bad files” keeps failing:

  1. The database. The full payload sits in the options table under a random option name, and `advanced-cache.php` reads it over a direct DB connection using the site’s own credentials
  2. Shared memory. A segment at a fixed numeric key holds readable PHP. It survives a file wipe and a database clean, and on shared hosting the segment can belong to a different account entirely, which makes it awkward to purge at all

Command and control over Ethereum

Instead of one hardcoded server, SC carries a list of roughly twenty public Ethereum RPC gateways and reads its instructions from smart contracts. Block one gateway and nineteen still answer, and there is no domain to sinkhole.

What it does with those instructions is the commercial part: it fingerprints the site (URL, host, WordPress and plugin versions, active theme, mu-plugin list, admin session tokens), creates a hidden administrator with valid auth cookies, hides itself from the plugin list and update transients, deactivates security plugins, and accepts front-end JavaScript — which on a WooCommerce site means card skimming at checkout.

What agencies should actually check

  • Open `wp-content/db.php` and `wp-content/advanced-cache.php` on any site you inherited. Those drop-ins are legitimate files; a large encoded block inside them is not
  • Grep configuration for `auto_prepend_file` in `.user.ini`, `php.ini` and `.htaccess`
  • Look at the bottom of the active theme’s `functions.php` for a fenced block
  • Compare the mu-plugins and plugins directories for the same plugin name appearing in both
  • List administrator accounts and check for one nobody recognises
  • Check the options table for a large random-named blob and any `sc_` prefixed rows
  • Watch egress for requests to public Ethereum RPC endpoints from a web server that has no business talking to one

Sucuri’s own removal order matters: neutralise the prepend directive first, then clear the database and shared-memory copies, then the cron hooks and the hidden admin, then the files in a single pass. Doing it in the other order takes the site down or leaves a seed behind. And if files reappear after a clean, that is not reinfection — it is a persistence point you missed, or an entry vector still open.

What this means for Codelibry clients

If you’re on one of our maintenance plans, these checks are part of the routine scan on your sites, and anything found is cleaned and written up in your next monthly maintenance report. There’s nothing for you to do here. If you’re not on a plan, this is the specific problem one solves: a cleanup is only finished when someone goes back a week later to confirm nothing grew back, and that second visit is usually the one nobody is paying for.

Source: Sucuri

Vitalii Omelchenko
Founder at Codelibry and WordPress enthusiast. Helping digital agencies to protect their margins and do better at website delivery. Need help with wordpress builds? Book a call using the Contact page
our Blog

Explore our Latest Insights

company icon
319 WordPress plugin vulnerabilities in one week. Fourteen were critical and one is still unpatched
News
October 2, 2026
company icon
How agency retainer billing cycle can 5x LTV
WordPress
September 30, 2026
company icon
Meet Ipsum, WordPress’s next default theme — and what else 7.2 has in store
News
September 29, 2026
whatsapp icon