cybersecuritynews.comยท23 september 2026
WordPress Malware Uses Hidden Plugin and Blockchain C2 to Stay Undetected

security
malware
Ethereum
Cyber Security News
administrator accounts
server-side backdoors
blockchain C2
hidden plugin
payment-related secrets
command-and-control
EtherHiding
WordPress vulnerabilities
WordPress
plugin takeover flaws
must-use plugin
Wordfence
cybersecuritynews.com
A new WordPress malware strain uses a hidden plugin, stolen admin access, and blockchain-based command-and-control to evade detection. The malware installs as a must-use plugin, making it invisible in the standard Plugins page and resilient to cleanup efforts. Researchers at Wordfence discovered it disguised as a health-check tool, with over 4,000 filenames including advanced-cache.php and functions.php. The malware can create admin accounts, steal passwords, and spread to other WordPress sites on the same server. Its command-and-control system uses EtherHiding on the Ethereum blockchain, enhancing its stealth and persistence.