According to security firm Sucuri, a highly persistent WordPress malware strain, dubbed 'SC' malware, is leveraging Ethereum infrastructure for command-and-control (C2) and self-healing. It maintains redundant copies across compromised sites, allowing it to rebuild itself even after cleanup attempts. Unlike traditional C2 servers, SC uses a list of approximately 20 public Ethereum RPC gateways, making it resilient to blocking efforts. The malware can also steal administrator session tokens, perform JavaScript injections to skim payment information on e-commerce sites, deactivate security software, and maintain administrator access.