Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain

Over 5,400 hacked sites serve malicious payloads stored on the blockchain, compromising thousands of users each day.

A massive cybercriminal operation has been leveraging thousands of compromised small-business websites to deliver malicious payloads stored in smart contracts on the BNB Smart Chain (BSC). Researchers at cloud security platform Netskope have identified over 5,400 hacked websites, mostly built on WordPress and PrestaShop, which were injected with a script that retrieves the next-stage payload from a smart contract on the BSC Testnet endpoint. This technique, known as EtherHiding, allows threat actors to store malicious code or configuration data in blockchain smart contracts, providing a resilient infrastructure that is difficult to take down.

The compromised websites display a fake CAPTCHA and instruct visitors to open the Windows Run dialog and paste a PowerShell command, which downloads and executes the final payload on the machine. The attackers store the payload in a smart contract, allowing them to modify it at any time. In some cases, the threat actor replaced the ClickFix payload with a WebRTC data-channel stager, which establishes a covert encrypted channel to the attacker and executes received code.

The operation uses more than 300 infected websites every day, with nearly 400 websites contacting the BSC Testnet RPC endpoints daily in August. This growth is alarming, and security researchers recommend that defenders block the entire pool of BSC testnet RPC endpoints to prevent further exploitation. Moreover, monitoring non-web UDP traffic associated with WebRTC can help identify potential threats.

This operation highlights the growing threat of using blockchain technology for malicious purposes. Smart contracts, designed to provide a transparent and secure way to execute code, are being exploited by attackers to store and execute malicious payloads. The use of EtherHiding and WebRTC stagers makes it challenging for defenders to detect and block these attacks.

To protect against such threats, it’s essential to stay informed about the latest attack vectors and tactics used by cybercriminals. Regular security updates, robust network monitoring, and employee education can help prevent successful exploitation of compromised websites. Additionally, blocking BSC testnet RPC endpoints and monitoring WebRTC traffic can help reduce the risk of falling victim to these attacks.

As we continue to see the misuse of blockchain technology for malicious purposes, it’s crucial to stay vigilant and adapt our security measures accordingly. By doing so, we can mitigate the impact of such operations and protect ourselves against the ever-evolving threats in the cyber world.


Source: Bleeping Computer — 2026-09-05