Inside a Malicious, Stealthy WordPress Must Use Plugin
The Wordfence Threat Intelligence Team identified an interesting malware sample in mid June during a site clean. TThe malware was installed as a must-use plugin with several self-healing mechanisms in place in order to survive removal
The Wordfence Threat Intelligence Team identified an interesting malware sample in mid June during a site clean. The malware was installed as a must-use plugin with several self-healing mechanisms in place in order to survive removal. It also makes use of Etherhiding, a technique that hides the location of the attacker’s servers behind a smart contract on the Ethereum blockchain, making the command channel resilient to takedown..
A malware detection signature was developed and released after undergoing our Q&A process on June 23rd 2026. All Wordfence Premium, Wordfence Care, and Wordfence Response customers received this signature immediately. Users of the free versions of Wordfence received the same signatures after the standard 30-day delay.