Researchers have documented a remote-access trojan called ChainScript that combines ClickFix social engineering, Node.js tooling and a Polygon smart contract used to locate its current command-and-control server.
The malware has appeared under several build names, including ComponentTask33, UpdateDigital, HostShared and OrchidViolet66, while impersonating familiar applications such as Spotify, Zoom Workplace and Microsoft Teams.
From ClickFix lure to persistent access
The observed chain starts with a ClickFix-style prompt that persuades the target to download and execute a malicious Windows Installer package through msiexec.exe. A sample disguised as Spotify installed the Node.js runtime and launched the JavaScript agent through hidden PowerShell and VBScript stages.
The malware stored components in Microsoft-looking paths under %LOCALAPPDATA%, then established user-level persistence with a scheduled task and a Registry Run key fallback.
Once active, ChainScript connects over WebSockets and gives operators interactive CMD and PowerShell access. It can manage files, capture screenshots, deploy more payloads, inventory desktop and browser cryptocurrency wallets, execute JavaScript remotely, update itself and remove its persistence.
Blockchain as resilient infrastructure
Instead of hard-coding a server address, ChainScript reads a Polygon smart contract to discover the current WebSocket endpoint. The operator can redirect infected machines to new infrastructure by updating the external resolver while leaving the malware unchanged.
This EtherHiding-style technique complicates domain- and IP-based blocking. It also allows attackers to rotate backend servers without rebuilding or redistributing the implant.
Detection and response guidance
- Train users not to paste commands or launch installers to fix browser or meeting errors.
- Monitor
msiexec.exelaunches initiated from browsers, chat clients or unusual parent processes. - Alert on hidden PowerShell and VBScript activity that installs Node.js in user-profile paths.
- Look for newly created scheduled tasks and Run keys associated with JavaScript launchers.
- Inspect unexpected Polygon RPC traffic and outbound WebSocket connections from Node.js.
- Use behavioral detections and endpoint telemetry rather than depending on fixed command-and-control indicators.
Blackpoint’s researchers said the campaign reflects a wider shift toward development frameworks and decentralized discovery mechanisms that make malware infrastructure easier to rotate and harder to disrupt.
Sources
- The Hacker News: ClickFix Lures Deploy ChainScript RAT
- Blackpoint Cyber: ChainScript — tracing a Node.js RAT across the blockchain
