Home › Intelligence › Brief
BREACH BRIEF🟠 High ThreatIntel

ChainScript RAT Uses Polygon Smart Contract to Hide Its C2 Server

Blackpoint discovered a Node.js remote‑access trojan that queries a Polygon smart contract for its command server, allowing attackers to rotate C2 endpoints instantly. The technique highlights the need for continuous monitoring of blockchain‑related outbound traffic as part of a control‑assurance program.

LiveThreat™ Intelligence · 📅 September 21, 2026· 📰 securityaffairs.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
2 recommended
📰
Source
securityaffairs.com

ChainScript RAT Uses Polygon Smart Contract to Hide Its C2 Server

What Happened — Blackpoint’s research team uncovered a new Node.js‑based remote‑access trojan, dubbed ChainScript, that retrieves its command‑and‑control (C2) endpoint from a public Polygon smart contract. The malware is delivered via a fake “Spotify” installer that runs without administrative rights and then queries the blockchain for a WebSocket address that can be rotated at will.

Why It Matters for Trust & Control Assurance

  • The technique bypasses traditional network‑based blocklists because the C2 address is not hard‑coded; it is resolved dynamically from a public ledger.
  • Continuous monitoring of outbound connections and logging of blockchain‑related DNS or RPC calls become essential control evidence for detecting such “EtherHiding” activity.
  • Mapping this detection requirement to a single control objective (monitoring of unauthorized external communications) satisfies multiple framework clauses simultaneously, providing a defensible audit trail.

Who Is Affected – Any organization that allows user‑level software installation on corporate endpoints, especially those with limited application whitelisting or endpoint monitoring (e.g., enterprise IT, SaaS providers, managed service firms).

Recommended Actions

  • Extend network‑traffic monitoring to include outbound calls to blockchain nodes and smart‑contract query endpoints.
  • Enforce strict application‑allow lists that block unsigned Node.js runtimes and unknown installers.
  • Capture and retain logs of RPC calls to public blockchains for at least 30 days to support forensic analysis.

Source: SecurityAffairs – ChainScript RAT

Technical Notes

  • Malware delivery: social‑engineering prompt to run a msiexec.exe command that downloads a disguised installer.
  • Execution chain: PowerShell → VBScript → bundled Node.js runtime (no admin rights required).
  • C2 resolution: eth_call to Polygon contract 0xf9099d0d747368cce8C10226CC9AF2bFD4DDbCF4 (chain ID 137) using selector 0x4ab7874e; response contains a ws:// or wss:// endpoint.
  • No CVE is associated; the threat lies in the novel use of blockchain as a dynamic resolver.
📰 Original Source
https://securityaffairs.com/199471/malware/chainscript-the-rat-that-hides-its-command-server-inside-a-blockchain-contract.html ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Answer one control objective. Answer ten frameworks.

The Verisq Common Framework is a spine of 84 control objectives that SOC 2, ISO 27001, NIST CSF, CMMC, HIPAA, PCI DSS, HITRUST, GDPR, ISO 42001 and NIST AI RMF map onto — each graded honestly. Satisfy an objective once and every framework that recognizes it lights up at its real strength.

See how the Verisq Common Framework works →