security1 distinct publisher
5,400 hacked WordPress and PrestaShop sites pull their ClickFix payload from a BNB testnet contract
The contract cannot be deleted. Every injected site has to reach a public BNB Smart Chain testnet RPC endpoint to read it. Netskope recommends blocking that pool. The payload has already changed once.
Publishers:bleepingcomputer.com
Reality
- Evidence52
- Adoption64
- Hype gap+14
- Incentives58