← All articles

New ChainScript trojan hides command server in a Polygon blockchain smart contract

Blackpoint researchers documented ChainScript, a previously unseen remote access trojan spread through ClickFix-style lures that impersonate Spotify, Zoom, and Microsoft Teams. It uses an EtherHiding-style technique, querying a Polygon smart contract to locate its active WebSocket command infrastructure so operators can rotate servers without changing the malware. The chain starts with a ClickFix lure leading to a malicious MSI run through msiexec, which deploys a Node.js runtime and launches a JavaScript agent through hidden PowerShell and VBScript stages dropped into Microsoft-looking paths under LOCALAPPDATA. ChainScript offers interactive command shells, file operations, screenshots, remote JavaScript, and enumeration of cryptocurrency wallets in both desktop applications and browser extensions.

Check
Block ClickFix-style paste-to-run lures, alert on msiexec spawning Node.js with PowerShell and VBScript stages, and review crypto wallet exposure on developer endpoints.
Affected
Users tricked by fake Spotify, Zoom, or Teams ClickFix lures run an MSI that installs a resilient RAT enumerating desktop and browser crypto wallets.
Fix
Restrict msiexec and script interpreters, monitor outbound blockchain RPC from endpoints, and educate staff against copy-paste terminal or run-dialog instructions.