MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-09-05 · via BleepingComputer

Blockchain-stored ClickFix payloads delivered via thousands of compromised sites

Image via BleepingComputer
Image via BleepingComputer

A cybercriminal operation has compromised over 5,400 websites, mostly WordPress and PrestaShop, to deliver ClickFix payloads stored in smart contracts on BNB Smart Chain testnet. The technique, EtherHiding, allows attackers to update malicious code dynamically. Later variants use WebRTC data channels for covert communication.

Expanded Detail

The campaign's scale is notable, with daily activity exceeding 300 compromised sites and peaking at 536 in August. The initial breach vector remains unidentified, though the affected platforms are predominantly WordPress and PrestaShop.

The later WebRTC variant bypasses standard handshakes by crafting a fake reply, enabling a covert channel. Received JavaScript is executed directly in browser memory, avoiding disk storage, while defenders are advised to block specific testnet endpoints and watch for unusual UDP traffic.

Context

Small business owners relying on WordPress or PrestaShop could face prolonged exposure, as blockchain-hosted payloads resist standard takedown efforts. Visitors who follow the fake CAPTCHA instructions may unknowingly install malware, potentially leading to credential theft or ransomware. This technique could erode trust in smaller e-commerce sites, while security teams may need to invest in more sophisticated monitoring to detect covert WebRTC traffic, increasing operational costs for organizations.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at BleepingComputer →
This summary is AI-generated and original to Mobble; the linked article is the authoritative source. Original headline: “Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain.” Browse more stories.