# ChainScript malware uses Polygon contract to rotate control servers

_Published Monday, September 21, 2026 at 6:06 AM EDT · Security · Latest · Tier 2 — Notable_

![ChainScript malware uses Polygon contract to rotate control servers — Primary](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi-cgmwQRZh142Z19A3s7K7tpaXtsyy6Imy9cYGM7nFP1DAZoSK9gDw8T0dGXlkFWOGDFShJWMNjC7jbwoSvLokr1pX27u2B1SABpBL-aWtaXj2hYYrqVwTE7LpEDn_iIbRYCro8sH2hzAEsjHLGkpFqTjEKlFHi2o2pgacFJQvYkPDCKVEhkJgW8OWhpZA/s1700-nu-rw-lo-l85-e365/poly.jpg)

Security researchers have identified ChainScript, a previously undocumented remote-access trojan delivered through ClickFix-style lures and installers disguised as Spotify, Zoom Workplace or Microsoft Teams. The malware gives operators command-line access, file control, screenshot capture, payload deployment, remote JavaScript execution and cryptocurrency-wallet discovery.

ChainScript consults a Polygon smart contract to locate its active WebSocket command server, allowing operators to redirect infected hosts without changing the implant. The attack requires a victim to execute a malicious Windows installer, which deploys a Node.js runtime and establishes user-level persistence through a scheduled task or Registry Run key.

## Sources

- [The Hacker News](https://thehackernews.com/2026/09/clickfix-lures-deploy-chainscript-rat.html)

---
Canonical: https://techandbusiness.org/newswire/aWX6sxxuanmUiaL8Jv8e0F
Published: 2026-09-21T10:06:51.878Z
Story chronology: 2026-09-21T08:39:38.000Z
Retrieved: 2026-09-21T13:29:04.661Z
Publisher: Tech & Business (techandbusiness.org)
