ClickFix Lures Deploy ChainScript RAT Using Polygon to Rotate C2 Infrastructure
Researchers uncover ChainScript, a Node.js RAT delivered through ClickFix lures that uses a Polygon smart contract to dynamically locate and rotate its WebSocket C2 infrastructure.

Cybersecurity researchers have uncovered a previously undocumented Node.js-based remote access trojan (RAT) called ChainScript, distributed through ClickFix-style social engineering attacks and designed to use the Polygon blockchain to dynamically locate its command-and-control (C2) infrastructure.
Researchers from Blackpoint's Adversary Pursuit Group (APG) identified the malware while investigating a ClickFix campaign. ChainScript has appeared under names including ComponentTask33, UpdateDigital, HostShared, and OrchidViolet66, while masquerading as legitimate software such as Spotify, Zoom Workplace, and Microsoft Teams.
How the Attack Works
The infection begins with a ClickFix lure, which tricks a victim into manually executing a malicious command.
The observed attack chain follows:
ClickFix lure → msiexec.exe → Malicious MSI → PowerShell → VBScript → Node.js runtime → ChainScript RAT
In one observed campaign, the malicious installer was named ComponentTask33-4d14e6ac.msi and disguised as Spotify.
The installer deploys a bundled Node.js runtime and ChainScript's JavaScript components into Microsoft-looking directories under %LOCALAPPDATA%. Hidden PowerShell and VBScript stages are then used to launch the malware.
ChainScript establishes user-level persistence through a scheduled task, with a Windows Registry Run key available as a fallback. The malware does not require administrator privileges for the observed installation process.
Polygon Blockchain Used to Find C2 Servers
ChainScript's most notable capability is its EtherHiding-style C2 discovery mechanism.
Instead of embedding a fixed command-and-control domain or IP address inside the malware, ChainScript queries a smart contract on the Polygon blockchain to obtain the address of its currently active WebSocket C2 server.
The process works roughly as follows:
ChainScript → Polygon smart contract → Active C2 address → WebSocket connection → Attacker commands
This allows operators to change their C2 infrastructure by updating the smart contract rather than modifying and redistributing the malware.
As a result, simply blocking a known malicious IP address may not permanently disrupt an infection because compromised systems can query the blockchain again for updated infrastructure.
ChainScript RAT Capabilities
Once connected to its C2 infrastructure, ChainScript provides attackers with extensive control over the compromised Windows system, including:
- Interactive CMD and PowerShell access
- File upload, download, and manipulation
- Screenshot capture
- Additional payload deployment
- Remote JavaScript execution
- System reconnaissance
- Cryptocurrency wallet enumeration
- Browser-extension wallet discovery
- Malware self-updates
- Persistence removal
The cryptocurrency functionality includes searching for both desktop wallet applications and browser-based wallet extensions, indicating that financial and cryptocurrency data may be among the information of interest to its operators.
What Security Teams Should Monitor
Organizations should watch for behavior associated with the infection chain, particularly:
msiexec.exedownloading or executing unexpected MSI packages- Hidden PowerShell execution
wscript.exeor suspicious VBScript activity- Node.js running from unusual
%LOCALAPPDATA%locations - Unexpected scheduled-task creation
- Registry Run-key modifications
- WebSocket connections from unusual processes
- Blockchain RPC traffic from endpoints that normally have no reason to access Polygon
- Software installers received through browser verification or update prompts
Defenders should also train users to recognize ClickFix attacks. Legitimate CAPTCHA, browser, Teams, Zoom, or software-update processes should not require users to open the Windows Run dialog and paste commands supplied by a website.
Security Takeaway
ChainScript demonstrates how attackers are combining social engineering, legitimate Windows utilities, modern development frameworks, and decentralized blockchain infrastructure.
Its C2 architecture is particularly significant:
ClickFix → Malicious MSI → Node.js RAT → Polygon Smart Contract → Rotating WebSocket C2
Using Polygon as a C2 discovery mechanism does not mean malicious commands themselves necessarily travel through the blockchain. Instead, the smart contract acts as a resolver that tells infected systems where the active attacker-controlled C2 server is located.
This makes behavioral monitoring and endpoint telemetry increasingly important because traditional static domain and IP blocklists may quickly become outdated.
Related reporting
Attackers Abuse ChatGPT Custom GPTs to Deliver RAT Malware via ClickFix
Attackers abuse ChatGPT Custom GPTs and sponsored Google results to redirect victims to ClickFix pages that execute PowerShell and install remote access trojan malware.
Star Blizzard Targets 100+ Organizations With Fake Event Invites and CosmicPulse Backdoor
Russia-linked Star Blizzard targets more than 100 organizations using fake event invitations, the new RedFlick malware delivery technique and the CosmicPulse Windows backdoor.
101 Malicious npm Packages Secretly Add Developers to WhatsApp Groups
Researchers uncover 101 malicious npm packages in the PhantomSub campaign that abuse authenticated WhatsApp sessions to secretly add developers to attacker-controlled groups and channels.


