Inside a Malicious, Stealthy WordPress Must Use Plugin
Brief
The Wordfence Threat Intelligence Team identified an interesting malware sample in mid June during a site clean. The malware was installed as a must-use plugin with several self-healing mechanisms in place in order to survive removal.
It also makes use of Etherhiding, a technique that hides the location of the attacker’s servers behind a smart contract on the Ethereum blockchain, making the command channel resilient to takedown..
A malware detection signature was developed and released after undergoing our Q&A process on June 23rd 2026. All Wordfence Premium , Wordfence Care , and Wordfence Response customers received this signature immediately. Users of the free versions of Wordfence received the same signatures after the standard 30-day delay.
