New ChainScript Malware Leverages Blockchain Infrastructure
The trojan uses Polygon smart contracts to manage command-and-control operations, complicating security takedowns.
Updated on Sept. 21, 2026 in Cybersecurity

Live Poll
Do you trust that social media platforms are doing enough to keep advertisements safe for users?
Threat actors have deployed a new remote access trojan, ChainScript, which uses decentralized blockchain infrastructure for command-and-control communication. The malware, which masquerades as common software like Spotify and Zoom, was identified following a campaign where a compromised HBO Max Reddit account served 108 malicious advertisements.
Why it matters
By utilizing smart contracts on the Polygon blockchain, operators can decentralize their infrastructure to resist traditional server takedown efforts. This shift allows attackers to maintain uninterrupted control over infected machines even after individual network components are identified and blocked.
The malware establishes persistence through scheduled tasks and Registry Run keys, executing a Node.js-based JavaScript agent via PowerShell and VBScript. It performs file operations, captures screenshots, and enumerates cryptocurrency wallets using the blockchain for server coordination.
The players
Microsoft
A multinational technology corporation that develops the Windows and macOS operating systems, alongside enterprise security platforms and cloud infrastructure.
HBO Max
A premium streaming service whose official Reddit account was compromised to distribute malicious advertising.
A massive social news aggregation and discussion platform that acts as an advertising network for external entities.
The details
The infection sequence initiates with a ClickFix lure, which tricks users into downloading a malicious Windows installer. Once active, the ChainScript agent communicates with command-and-control servers through Polygon smart contracts, a method that distributes network management across a decentralized ledger. This architectural choice makes it difficult for defenders to isolate the primary command nodes, as the communication is baked into the blockchain's transaction logic rather than relying on standard, blockable IP addresses.
Timeline
Mid-September 2026: A verified Reddit account served 108 malicious ads over 48 hours.
August 2026: Microsoft documented separate macOS-based ClickFix campaigns.
The Tech Race
The emergence of ChainScript marks a departure from centralized botnet architectures toward decentralized command infrastructure. This development updates the tactical landscape previously defined by Microsoft's research into macOS ClickFix campaigns, extending the threat model into blockchain-enabled control.
Users should exercise extreme caution when encountering software downloads promoted through social media ads, even when they appear to originate from verified accounts. The risk is high for individuals in the United States, United Kingdom, Germany, Japan, and Canada, as these regions have been identified as primary targets for these ongoing campaigns.
The takeaway
The transition to smart-contract-based malware signals a hardening of botnet infrastructure against traditional domain-based blocklists. Security teams should monitor for anomalous outbound traffic to known blockchain transaction relayers rather than relying solely on legacy IP reputation metrics.
Further reading
For broader analysis on current threat landscapes, consult the latest research on Cybersecurity.
Live Poll
Do you trust that social media platforms are doing enough to keep advertisements safe for users?






