ChainScript: the RAT that hides its command server inside a blockchain contract
New Node.js RAT 'ChainScript' hides command server in Polygon smart contract, spreading via ClickFix campaigns with fake Spotify/Zoom installers.
Blackpoint's Adversary Pursuit Group discovered ChainScript, a previously undocumented Node.js remote access trojan (RAT) that uses EtherHiding techniques to conceal its command-and-control server within a Polygon blockchain smart contract. The malware spreads through ClickFix campaigns, tricking users into pasting commands that execute MSI installers disguised as legitimate software like Spotify, Zoom, and Microsoft Teams. Once installed, ChainScript provides operators with comprehensive access including interactive shell, file operations, screenshots, and cryptocurrency wallet reconnaissance.