WordPress Malware Uses Ethereum Gateways to Restore Hidden Components
The SC malware appeared in at least eight locations on one compromised site and can query a smart contract through roughly 20 public gateways.

A WordPress malware strain called SC can restore components after cleanup attempts and use public Ethereum gateways to receive instructions, giving it multiple ways to remain active on compromised sites.
SC was found in at least eight locations on one site, with copies stored across its files, database and server memory. A component that remains can recreate deleted files or database content when the site loads.
The malware's payload lists roughly 20 public Ethereum remote procedure call gateways. It uses them to query a smart contract for instructions, leaving alternate routes to its command system if one gateway is unavailable.
SC can collect WordPress and plugin version details, site information and administrator session tokens, then send encrypted data to its controller. The controller can return JavaScript for the site's front end, which may enable checkout skimming on online stores.
The malware can also hide plugin entries, disable and delete security plugins, and create hidden administrator accounts. The risk to compromised websites centers on the malware's ability to persist and receive remote instructions; no impact on Ethereum's network or its users generally is indicated.