Microsoft Threat Intelligence said hackers are abusing BNB Smart Chain to store and serve malware, injecting JavaScript into compromised websites that queries blockchain-hosted contracts.
"Microsoft Threat Intelligence has identified a cluster of compromised websites displaying ClickFix lures and using EtherHiding, a technique associated with the ClearFake campaign," the company said in a post on X on Aug. 6.
The injected, Base64-encoded JavaScript contacts a BNB Smart Chain RPC gateway to query a smart contract for the next stage of the payload, Microsoft said. Because content recorded in the contract can only be edited or removed by the private key of the wallet that deployed it, the infrastructure is largely immune to conventional takedown or government removal efforts.
To finish the infection, attackers present victims with a fake CAPTCHA that instructs them to open the Windows Run dialog, paste clipboard contents and execute an attacker-controlled command. The code hides its components through obfuscation while abusing native tools including PowerShell, Command Prompt, Windows Terminal, mshta and curl.
If the victim completes the execution, the infected system becomes exposed to a range of harmful software, including Lumma Stealer, XWorm, AsyncRAT and MintsLoader. Successful breaches allow mass credential extraction and open the door to manually operated ransomware attacks, Microsoft said.
Microsoft urged users to never paste commands from CAPTCHAs, browser warnings, advertisements or emails, and recommended organizations enable Microsoft Defender's network, web and cloud protections, restrict unnecessary command-line utilities and enable detailed PowerShell logging.
The alert extends a series of security warnings Microsoft has issued across the crypto ecosystem. In June, the company disclosed a "crypto clippers" campaign designed to swap copied wallet addresses for attacker-controlled ones. Months earlier, researchers revealed a large-scale cryptojacking network that combined SEO poisoning.
The campaign shows how blockchain infrastructure, prized for its immutability, can be turned against users. BNB Smart Chain, the network behind Binance's BNB token, now serves as a resilient command-and-control layer that security teams cannot easily dismantle, raising the stakes for Web3 projects that rely on the chain and for the enterprises that audit them. The disclosure may also prompt fresh scrutiny of how decentralized networks handle abuse, as regulators weigh whether infrastructure providers bear responsibility for malicious content recorded on-chain.
This article is for informational purposes only and does not constitute investment advice.