Malware-as-a-Smart-Contract – Part 1: Weaponising BSC to Target Windows Users via WordPress
ID: 2ed99e11-ad54-5fb9-9d9f-e25e37582471
STIX ID: report--2ed99e11-ad54-5fb9-9d9f-e25e37582471
Feed Name: JUMPSEC Labs
This report details an active campaign that compromises WordPress sites by embedding Base64-encoded, obfuscated JavaScript which shows a fake reCAPTCHA/ClickFix prompt to force user interaction; the script detects Windows victims, retrieves additional payloads from Binance Smart Chain smart contracts, decodes and evals them in-browser, and coerces victims to run remote mshta commands. The author provides technical analysis of the injection, payload decoding, cookie/UUID tracking logic, conditional blockchain checks used as a success gate, evidence of ongoing transactions to the implicated contracts (as of April 26, 2025), and an extensive list of IOC domains and IP addresses for detection and remediation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
