cybersecuritynews.comยท23 september 2026

WordPress Malware Uses Hidden Plugin and Blockchain C2 to Stay Undetected

Image for the article: WordPress Malware Uses Hidden Plugin and Blockchain C2 to Stay Undetected
Image via cybersecuritynews.com

A new WordPress malware strain uses a hidden plugin, stolen admin access, and blockchain-based command-and-control to evade detection. The malware installs as a must-use plugin, making it invisible in the standard Plugins page and resilient to cleanup efforts. Researchers at Wordfence discovered it disguised as a health-check tool, with over 4,000 filenames including advanced-cache.php and functions.php. The malware can create admin accounts, steal passwords, and spread to other WordPress sites on the same server. Its command-and-control system uses EtherHiding on the Ethereum blockchain, enhancing its stealth and persistence.