research
Published 2026-09-18
Verified 2026-09-21

Blackpoint APG: ChainScript Node.js RAT — ClickFix MSI lures + Polygon EtherHiding C2

Blackpoint Adversary Pursuit Group (Sam Decker, Andi Ursry, Nevan Beal; published 18 September 2026) tracks a previously unnamed Node.js remote access trojan as ChainScript, found while investigating ClickFix activity. Initial access: ClickFix lure → msiexec.exe pulling a malicious Windows Installer from api-configuard[.]com (capher.php + token) — builds observed as ComponentTask33, UpdateDigital, HostShared, OrchidViolet66, presenting as Spotify, Zoom Workplace, or Microsoft Teams. MSI (user context, ALLUSERS=2 / MSIINSTALLPERUSER=1) deploys a bundled Node.js runtime and launches the JavaScript agent via hidden PowerShell (._scatter.ps1) and VBScript (._agent.vbs → node.exe app/src/index.js). Scatter stages Microsoft-looking paths under %LOCALAPPDATA% / %APPDATA%. Persistence: hidden ComponentTask33Agent scheduled task at logon with HKCU Run-key fallback. RAT capabilities: interactive CMD/PowerShell, file ops, screenshots (SearchTrustedRuntimeSvc.exe), payload deploy, crypto wallet enumeration (desktop + browser extensions), remote JS execution, self-update and cleanup. C2: EtherHiding-style discovery via a Polygon smart contract that returns the active WebSocket panel at runtime so operators rotate backends without redeploying the implant. APG notes architectural kinship with Tsundere / EtherRAT (Node.js + blockchain C2) without claiming shared operators. Amplify: The Hacker News 21 September 2026. No CVE. Distinct from desk cards clickfix-etherhiding-bsc-20260905, hbo-max-reddit-clickfix-20260914, clickfix-vidar-wordpress, and guidepoint-etherhiding-polygon-20260917.

Product
ChainScript Node.js RAT (ClickFix → malicious MSI; Polygon smart-contract WebSocket C2)
Versions
n/a (malware; multiple build names / lures — ComponentTask33, UpdateDigital, HostShared, OrchidViolet66)
Exploited in Australia?
unknown
Patch to
Block ClickFix social-engineering (do not paste/run msiexec from untrusted prompts); hunt MSI/Node.js agents under Microsoft-looking LocalAppData/AppData paths and ComponentTask33Agent scheduled tasks / Run keys; monitor unusual Polygon/WebSocket C2 and api-configuard[.]com; treat Spotify/Zoom/Teams MSI downloads from non-vendor hosts as hostile.

Primary: Blackpoint APG — ChainScript: Tracing a Node.js RAT Through the Blockchain (18 Sep 2026) · Vendor: Blackpoint Cyber Adversary Pursuit Group primary analysis · The Hacker News — ClickFix / ChainScript / Polygon C2 amplify (21 Sep 2026)

tech identity network