Security1 distinct publisher3 min readPublished
The contract cannot be deleted. Every injected site has to reach a public BNB Smart Chain testnet RPC endpoint to read it. Netskope recommends blocking that pool. The payload has already changed once.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
EtherHiding puts the payload where takedown does not reach. A smart contract on a public chain has no host to serve an abuse notice on and no registrar to suspend, and Netskope describes that resilience as the point of the technique [3]. What the contract does have is a read path. Each of the injected scripts has to call a BSC Testnet RPC endpoint to get its next stage [2], and that is the control Netskope actually puts first: block the entire pool of testnet RPC endpoints, then watch for non-web UDP traffic associated with WebRTC [13]. Deleting the contract and cutting the fetch are different problems, and only one of them is available.
Netskope notes the BSC Testnet behaves like the production chain but is free to use [4], so rewriting the payload for every one of the 5,400 sites at once costs the operator nothing and needs no funded wallet [6]. The operator has already used that: later in the campaign the ClickFix payload in the contract was swapped for a WebRTC data-channel stager [7].
It creates a peer connection and a data channel and generates a session description offer as a normal handshake would, then, in Netskope's words, "hand-writes the answer itself and feeds it straight back into the connection," so no handshake with a remote peer occurs but a data channel to the attacker opens anyway [8]. It pulls JavaScript from a hardcoded C2, buffers it, and runs it when the channel closes or after ten seconds [9]. The code is assembled in browser memory and appended to the head of the DOM, never written to disk [10].
Netskope identified more than 5,400 compromised sites, says the operation uses over 300 daily, and measured close to 400 daily callers to the testnet RPC endpoints in August with an all-time peak of 536 [1][11][12]. That peak is 9.9 percent of the identified pool; the August average is 7.4 percent [15][16]. Roughly nine in ten known sites are idle on any given day, so scrubbing the hosts that appeared in yesterday's telemetry leaves the inventory intact.
One step in the first chain requires the victim: the fake CAPTCHA tells the visitor to open the Windows Run dialog and paste a PowerShell command, and the final payload does not download until they do [5]. That step is absent from Netskope's account of the newer variant, which executes received code in browser memory [17]. Blocking the paste covers the ClickFix delivery and not the stager that replaced it, which leaves two network controls carrying the campaign: the testnet RPC pool, and UDP egress from browsers that has no business existing on most corporate networks [13].
Ranked by verification strength, evidence, and original report placement.
Netskope researchers identified more than 5,400 hacked websites over the past months, most of them built on WordPress and PrestaShop.
Each compromised site was injected with a script that retrieves its next-stage payload from a smart contract via a BNB Smart Chain (BSC) Testnet endpoint, a technique known as EtherHiding.
Threat actors use EtherHiding to store malicious code or configuration data in blockchain smart contracts, providing a resilient infrastructure that is difficult to take down.
Netskope explains that the BSC Testnet is designed for developers and functions similarly to the mainnet production blockchain, but is available free of charge.
The injected script displays a ClickFix lure with a fake CAPTCHA that instructs visitors to open the Windows Run dialog and paste a PowerShell command; doing so downloads and executes the final payload on the machine.
Because the payload is stored in a smart contract, the attacker can modify it at any time.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · September 5, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
build
TerminalFix delivers its first stage through the clipboard of the person it targets1 distinct publisher
security
ClickFix lures now paste an msiexec command that installs legitimate software to sideload a DLL1 distinct publisher
build
GiveWP rebuilds an anonymous visitor's serialized object into command execution1 distinct publisher
invest
Check Point finds 2,000 hacked WordPress sites doing the hosting for a crypto-stealing toolkit2 distinct publishers
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Precise mechanics, one witness
The technical detail is specific enough to be wrong in checkable ways: a fabricated WebRTC answer fed back into the connection, a ten-second execution fallback, code appended to the DOM head. All of it comes from Netskope, quoted at length by BleepingComputer and examined by nobody else. No affected site, contract address or C2 host appears in the text, and the endpoint blocklist is referred to rather than listed, so a reader has no route to independent verification.
Running in the wild on one vendor's meter
The attacker side is the part with numbers attached: 300-plus sites in use per day, nearly 400 calling the testnet RPC daily in August, 536 at peak, and a line that has climbed since spring. Those are traffic observations from Netskope's own vantage point, which sets a floor rather than a size. The victim side remains undocumented, leaving infection counts and compromised businesses unnamed.
Framing outruns what was seen at once
Our headline count of 5,400 sits against a peak of 536 seen calling the contract in any single day, so the fleet described is roughly ten times anything measured active together. Our own summary line says the contract cannot be deleted, which is firmer than Netskope, whose wording is takedown-resistant rather than impossible. And the ClickFix label attaches to a stage the operator has already replaced with something quieter.
Vendor telemetry, vendor remedy
Netskope sells the cloud traffic inspection that produced these counts, and its advice -- block a pool of RPC endpoints, watch anomalous UDP -- describes network-layer work its own platform performs. The research holds up on its own terms, but the only measurement of scale comes from a party whose visibility is the product. The relaying page then closes on a pitch for an unrelated commercial security report and its 338 million simulations, which is what the surrounding real estate is selling.
Mechanism solid, totals an estimate
The described technique hangs together and is detailed enough that a defender can act on it today. The counts, the growth trend and the mid-campaign change in what the contract serves all depend on one vendor's window into the traffic, with no second reading and no published indicators, and the unknown initial access vector means the reported fleet size cannot be reasoned about from the platform side either. The mechanics stand as reliable, while every number here functions as a lower bound.