Blockchain-stored ClickFix payloads delivered via thousands of compromised sites

A cybercriminal operation has compromised over 5,400 websites, mostly WordPress and PrestaShop, to deliver ClickFix payloads stored in smart contracts on BNB Smart Chain testnet. The technique, EtherHiding, allows attackers to update malicious code dynamically. Later variants use WebRTC data channels for covert communication.
The campaign's scale is notable, with daily activity exceeding 300 compromised sites and peaking at 536 in August. The initial breach vector remains unidentified, though the affected platforms are predominantly WordPress and PrestaShop.
The later WebRTC variant bypasses standard handshakes by crafting a fake reply, enabling a covert channel. Received JavaScript is executed directly in browser memory, avoiding disk storage, while defenders are advised to block specific testnet endpoints and watch for unusual UDP traffic.
Small business owners relying on WordPress or PrestaShop could face prolonged exposure, as blockchain-hosted payloads resist standard takedown efforts. Visitors who follow the fake CAPTCHA instructions may unknowingly install malware, potentially leading to credential theft or ransomware. This technique could erode trust in smaller e-commerce sites, while security teams may need to invest in more sophisticated monitoring to detect covert WebRTC traffic, increasing operational costs for organizations.