5,400+ hacked WordPress and PrestaShop sites push ClickFix malware via BNB Smart Chain
Netskope researchers found over 5,400 compromised small-business websites, mostly running WordPress and PrestaShop, injected with scripts that fetch malicious payloads from smart contracts on the BNB Smart Chain Testnet. Visitors are shown a fake CAPTCHA that tricks them into pasting a PowerShell command via the Windows Run dialog, which downloads and runs the attacker's final payload. Later in the campaign, attackers swapped the ClickFix payload for a stealthier WebRTC data-channel stager that opens a covert encrypted connection without a genuine handshake.