thehackernews.com
ClickFix Lures Deploy ChainScript RAT Using Polygon to Rotate C2 Infrastructure
Threat actors are using ClickFix‑style lures to deliver a new remote‑access trojan dubbed ChainScript. The malware, also seen under names such as ComponentTask33 and OrchidViolet66, masquerades as legitimate software like Spotify, Zoom Workplace and Microsoft Teams. After a malicious MSI installer runs via msiexec.exe, it drops a Node.js runtime and launches a JavaScript agent through hidden PowerShell and VBScript stages, installing components in “%LOCALAPPDATA%” and persisting via a scheduled task with a Registry Run key fallback. ChainScript employs [...]