The Wordfence Threat Intelligence Team identified an interesting malware sample in mid June during a site clean. The malware was installed as a must-use plugin with several self-healing mechanisms in place in order to survive removal. It also makes use of Etherhiding, a technique that hides the location of the attacker’s servers behind a smart contract on the Ethereum blockchain, making the command channel resilient to takedown..
Inside a Malicious, Stealthy WordPress Must Use Plugin
About this summary. This is a short, independently written summary of an article first published by Wordfence. Cyber Security News did not report or verify the underlying story. Read the original: https://www.wordfence.com/blog/2026/09/inside-a-malicious-stealthy-wordpress-must-use-plugin/

Source attribution: headline and facts are from Wordfence (wordfence.com). Summary method: excerpt of the source description. See our source attribution policy.





