SC Malware Exploits Public Ethereum Gateways to Remain Active
A malicious strain of WordPress malware called SC has been discovered to have multiple ways to remain active on compromised sites. The malware, found in at least eight locations on one site, can restore components after cleanup attempts and use public Ethereum gateways to receive instructions.
The payload lists roughly 20 public Ethereum remote procedure call gateways that the malware uses to query a smart contract for instructions. This leaves alternate routes to its command system if one gateway is unavailable.
The SC malware can collect WordPress and plugin version details, site information, and administrator session tokens, then send encrypted data to its controller. The controller can return JavaScript for the site's front end, which may enable checkout skimming on online stores.