Home › Intelligence › Brief
BREACH BRIEF🟠 High ThreatIntel

ChainScript RAT Spread via Fake Spotify, Zoom and Teams Installers Using Polygon Smart Contracts

Blackpoint Cyber uncovered a Node.js RAT called ChainScript being distributed through fake installers for Spotify, Zoom and Microsoft Teams. The malware leverages Polygon blockchain contracts to resolve its command‑and‑control server, highlighting a supply‑chain control weakness that impacts any organization allowing end‑user software installs.

LiveThreat™ Intelligence · 📅 September 22, 2026· 📰 hackread.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
3 sector(s)
✅
Actions
4 recommended
📰
Source
hackread.com

ChainScript RAT Spread via Fake Spotify, Zoom and Teams Installers Using Polygon Smart Contracts

What Happened – Researchers at Blackpoint Cyber identified a new Node.js‑based remote‑access trojan, ChainScript, being delivered through counterfeit installers for popular desktop apps (Spotify, Zoom, Microsoft Teams). The malware embeds references to Polygon blockchain smart contracts that dynamically resolve the attacker‑controlled C2 server address.

Why It Matters for Trust & Control Assurance

  • The campaign exploits a software‑supply‑chain control gap – organizations often trust “official‑looking” installers without verifying code‑signing or provenance.
  • Continuous third‑party risk monitoring and evidence of due‑diligence (e.g., signed‑binary verification, blockchain‑based C2 detection) are precisely the controls a trust‑assurance program must document.
  • Mapping this incident to the NIST CSF 2.0 Identify → Supply Chain Risk Management objective shows how a single control can address many regulatory frameworks.

Who Is Affected – Enterprises of any size that allow employees to download and install productivity or media software, especially those in technology, finance, and professional services.

Recommended Actions

  • Enforce strict code‑signing validation for all downloaded executables; block unsigned installers.
  • Deploy a software‑bill‑of‑materials (SBOM) solution and continuously monitor third‑party binaries for tampering.
  • Integrate blockchain‑watching alerts into your SOC to flag anomalous smart‑contract lookups.
  • Update your vendor‑risk inventory to include “installer distribution channels” and require attestations of secure build pipelines.

Source: HackRead – ClickFix Attacks Spread ChainScript RAT via Fake Spotify and Teams Installers

Technical Notes – ChainScript is built on Node.js, packaged as a disguised installer, and contacts a Polygon smart contract to retrieve the current C2 endpoint. No public CVE is associated; the threat leverages social engineering and supply‑chain deception rather than a software vulnerability.

📰 Original Source
https://hackread.com/clickfix-chainscript-rat-fake-spotify-teams-installers/ ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Vendor Risk Hub

Point-in-time vendor reviews miss incidents like this.

Verisq AI Trust Operations replaces the annual questionnaire with continuous third-party monitoring — so vendor exposure becomes audit evidence, not a once-a-year guess.

See how Verisq AI Trust Operations works →