Skip to main content
The Wire
CyberNews by Zentrya One
Malware

ClickFix Lures Deploy ChainScript RAT Using Polygon to Rotate C2 Infrastructure

Researchers uncover ChainScript, a Node.js RAT delivered through ClickFix lures that uses a Polygon smart contract to dynamically locate and rotate its WebSocket C2 infrastructure.

Cybersecurity researchers have uncovered a previously undocumented Node.js-based remote access trojan (RAT) called ChainScript, distributed through ClickFix-style social engineering attacks and designed to use the Polygon blockchain to dynamically locate its command-and-control (C2) infrastructure.

Researchers from Blackpoint's Adversary Pursuit Group (APG) identified the malware while investigating a ClickFix campaign. ChainScript has appeared under names including ComponentTask33, UpdateDigital, HostShared, and OrchidViolet66, while masquerading as legitimate software such as Spotify, Zoom Workplace, and Microsoft Teams.

How the Attack Works

The infection begins with a ClickFix lure, which tricks a victim into manually executing a malicious command.

The observed attack chain follows:

ClickFix lure → msiexec.exe → Malicious MSI → PowerShell → VBScript → Node.js runtime → ChainScript RAT

In one observed campaign, the malicious installer was named ComponentTask33-4d14e6ac.msi and disguised as Spotify.

The installer deploys a bundled Node.js runtime and ChainScript's JavaScript components into Microsoft-looking directories under %LOCALAPPDATA%. Hidden PowerShell and VBScript stages are then used to launch the malware.

ChainScript establishes user-level persistence through a scheduled task, with a Windows Registry Run key available as a fallback. The malware does not require administrator privileges for the observed installation process.

Polygon Blockchain Used to Find C2 Servers

ChainScript's most notable capability is its EtherHiding-style C2 discovery mechanism.

Instead of embedding a fixed command-and-control domain or IP address inside the malware, ChainScript queries a smart contract on the Polygon blockchain to obtain the address of its currently active WebSocket C2 server.

The process works roughly as follows:

ChainScript → Polygon smart contract → Active C2 address → WebSocket connection → Attacker commands

This allows operators to change their C2 infrastructure by updating the smart contract rather than modifying and redistributing the malware.

As a result, simply blocking a known malicious IP address may not permanently disrupt an infection because compromised systems can query the blockchain again for updated infrastructure.

ChainScript RAT Capabilities

Once connected to its C2 infrastructure, ChainScript provides attackers with extensive control over the compromised Windows system, including:

  • Interactive CMD and PowerShell access
  • File upload, download, and manipulation
  • Screenshot capture
  • Additional payload deployment
  • Remote JavaScript execution
  • System reconnaissance
  • Cryptocurrency wallet enumeration
  • Browser-extension wallet discovery
  • Malware self-updates
  • Persistence removal

The cryptocurrency functionality includes searching for both desktop wallet applications and browser-based wallet extensions, indicating that financial and cryptocurrency data may be among the information of interest to its operators.

What Security Teams Should Monitor

Organizations should watch for behavior associated with the infection chain, particularly:

  • msiexec.exe downloading or executing unexpected MSI packages
  • Hidden PowerShell execution
  • wscript.exe or suspicious VBScript activity
  • Node.js running from unusual %LOCALAPPDATA% locations
  • Unexpected scheduled-task creation
  • Registry Run-key modifications
  • WebSocket connections from unusual processes
  • Blockchain RPC traffic from endpoints that normally have no reason to access Polygon
  • Software installers received through browser verification or update prompts

Defenders should also train users to recognize ClickFix attacks. Legitimate CAPTCHA, browser, Teams, Zoom, or software-update processes should not require users to open the Windows Run dialog and paste commands supplied by a website.

Security Takeaway

ChainScript demonstrates how attackers are combining social engineering, legitimate Windows utilities, modern development frameworks, and decentralized blockchain infrastructure.

Its C2 architecture is particularly significant:

ClickFix → Malicious MSI → Node.js RAT → Polygon Smart Contract → Rotating WebSocket C2

Using Polygon as a C2 discovery mechanism does not mean malicious commands themselves necessarily travel through the blockchain. Instead, the smart contract acts as a resolver that tells infected systems where the active attacker-controlled C2 server is located.

This makes behavioral monitoring and endpoint telemetry increasingly important because traditional static domain and IP blocklists may quickly become outdated.

Filed by Zentrya One Desk · CyberNews desk  ·  Follow Zentrya One on LinkedIn

Related reporting

The Daily Brief

Stay informed. Stay prepared. Stay one step ahead.

One brief each morning: the advisories that matter, the noise removed.

Double opt-in. One-click unsubscribe in every email. We never sell addresses.