Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain

Over 5,400 hacked websites are being used as unwitting accomplices in a massive cybercrime operation that’s delivering malicious payloads stored on the BNB Smart Chain (BSC) blockchain. This sprawling campaign involves thousands of compromised small-business sites, with most built on WordPress and PrestaShop platforms.

Researchers at cloud security firm Netskope have uncovered the scope of this operation, which has been ongoing for months. The compromised websites were initially injected with a script that retrieves its next-stage payload from a smart contract on the BSC Testnet endpoint. This technique is known as EtherHiding, and it allows threat actors to store malicious code or configuration data in blockchain smart contracts – making it difficult for security teams to take down.

Here’s how it works: when a visitor arrives at one of these hacked sites, they’re presented with a fake CAPTCHA and instructed to open the Windows Run dialog. This action downloads and executes a PowerShell command, which then fetches the final payload from the smart contract on the BSC Testnet. The beauty of this approach lies in its flexibility – because the attacker stores the payload in a smart contract, they can modify it at any time.

In recent days, Netskope researchers have observed that the attackers have replaced the ClickFix payload with a WebRTC data-channel stager. This newer variant establishes a covert encrypted channel to the attacker and executes the received code without requiring a traditional handshake. The script creates a peer connection, generates a session description offer, and feeds it straight back into the connection – essentially bypassing any real-time verification.

The operation is staggering in its scale, with over 300 infected websites being used every day. Since spring, the number of compromised sites contacting the BSC Testnet RPC endpoints has grown constantly, peaking at 536 in August alone. This alarming trend highlights the need for webmasters and security teams to take immediate action.

Netskope recommends that defenders block the entire pool of BSC testnet RPC endpoints and monitor for non-web UDP traffic associated with WebRTC. However, this may not be enough – as the report notes, even when attackers have valid credentials, only 37% of their actions are blocked by standard prevention measures. This underscores the importance of staying vigilant and adapting to emerging threats.

For small-business owners and website administrators, this serves as a stark reminder that even seemingly innocuous websites can become unwitting participants in large-scale cybercrime operations. The takeaway is clear: stay up-to-date on security patches, monitor your sites’ traffic closely, and be prepared to adapt to new threats as they emerge – the consequences of inaction can be devastating.


Source: Bleeping Computer — 2026-09-05