Over 5,400 Hacked Sites Use Blockchain Smart Contracts to Deliver Malware
More than 5,400 compromised websites, including those built on WordPress and PrestaShop, have been found fetching malicious payloads stored on BNB Smart Chain Testnet smart contracts, according to Netskope Threat Labs. Attackers embed hidden loader scripts into legitimate site code, which silently query blockchain smart contracts via JSON-RPC calls when unsuspecting visitors load the page. One attack vector, known as ClickFix, displays a fake CAPTCHA screen that tricks users into pasting a PowerShell command into the Windows Run dialog, ultimately downloading and executing a final malware payload. A second variant exploits WebRTC data channels to deliver and run JavaScript directly in the browser without leaving standard network traces like DNS or STUN signaling. Using blockchain as a distribution layer allows attackers to update malicious content across thousands of sites from a single location, making detection and takedown significantly harder.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in