The Wordfence Threat Intelligence Team identified an interesting malware sample in mid June during a site clean. The malware was installed as a must-use plugin with several self-healing mechanisms in place in order to survive removal.
Read The Full Post Here
In the full post, we walk through why must-use plugins are such an attractive hiding place for attackers. Because must-use plugins load automatically on every request and do not appear alongside normal plugins in the WordPress admin, a site owner can look at their plugins screen and see nothing out of the ordinary while malicious code runs on every single page load.
We then break down the self-healing behavior that made this sample stand out. The malware plants multiple copies of itself and hooks into WordPress in ways that allow it to rewrite deleted files and restore its own presence, meaning a partial cleanup simply invites the infection to come back. We explain the mechanisms involved and what that means for anyone attempting a manual removal.
The post also covers the data theft and remote control functionality built into the plugin, including how it communicates with the attacker’s infrastructure and what information is at risk once a site is compromised.
It also makes use of Etherhiding, a technique that hides the location of the attacker’s servers behind a smart contract on the Ethereum blockchain, making the command channel resilient to takedown. We explain how this works in practice and why blocklisting a single domain or IP address is not enough to cut off the attacker.
Finally, we provide practical guidance on detection and cleanup, including where to look on your own site, the indicators of compromise to watch for, and the steps to fully remove this infection rather than temporarily suppressing it.
A malware detection signature was developed and released after undergoing our Q&A process on June 23rd 2026. All Wordfence Premium, Wordfence Care, and Wordfence Response customers received this signature immediately.
Users of the free versions of Wordfence received the same signatures after the standard 30-day delay.
