ChainScript: the RAT that hides its command server inside a blockchain contract
New Node.js RAT 'ChainScript' hides command server in Polygon smart contract, spreading via ClickFix campaigns with fake Spotify/Zoom installers.
Blackpoint's Adversary Pursuit Group discovered ChainScript, a previously undocumented Node.js remote access trojan (RAT) that uses EtherHiding techniques to conceal its command-and-control server within a Polygon blockchain smart contract. The malware spreads through ClickFix campaigns, tricking users into pasting commands that execute MSI installers disguised as legitimate software like Spotify, Zoom, and Microsoft Teams. Once installed, ChainScript provides operators with comprehensive access including interactive shell, file operations, screenshots, and cryptocurrency wallet reconnaissance.
- ChainScript is a Node.js RAT that uses Polygon blockchain smart contracts for command server discovery.
- Infection vector uses ClickFix social engineering to execute malicious MSI installers disguised as Spotify, Zoom, or Teams.
- Malware provides full interactive shell, file access, screenshots, and crypto wallet reconnaissance.
- Attacker can rotate command-and-control infrastructure by updating the smart contract without modifying malware.
- Blackpoint researchers observed live C2 rotation during analysis.
Coverage timelineoldest first · each row is one article
- · 5d agoClickFix Lures Deploy ChainScript RAT Using Polygon to Rotate C2 Infrastructure
The Hacker News· 65
Blackpoint details new ChainScript RAT spread via ClickFix lures that uses a Polygon smart contract to rotate C2 infrastructure.
- · 5d agoChainScript: the RAT that hides its command server inside a blockchain contract
Security Affairs· 72
New Node.js RAT 'ChainScript' hides command server in Polygon smart contract, spreading via ClickFix campaigns with fake Spotify/Zoom installers.