Attackers have compromised more than 5,400 small-business websites and are using them to trick visitors into infecting their own Windows computers. Netskope says most affected sites run WordPress or PrestaShop and were injected with scripts that fetch next-stage payloads from BNB Smart Chain Testnet smart contracts using the EtherHiding technique. The campaign shows fake CAPTCHA prompts in a ClickFix lure, tells users to paste a PowerShell command into Windows Run, and has also shifted to a WebRTC-based stager that pulls code through an encrypted browser channel.
Why it matters: This matters to both website owners and everyday visitors because compromised sites can turn routine browsing into a malware trap. Defenders should hunt for the listed BSC Testnet remote procedure call endpoints and unusual WebRTC traffic, while site operators should check WordPress and PrestaShop sites for unauthorized script injections and users should never paste commands from CAPTCHA pages.
Bill Toulas
2026.09.05
100% relevant
This article establishes a distinct large-scale malware delivery operation centered on thousands of already-compromised websites, blockchain-hosted payloads, and ClickFix social-engineering lures.
← Back to all stories