Cyber Threat Brief — September 21 2026

⚠️ This report is AI-generated. Always validate findings.

1. ChainScript Node.js RAT — ClickFix + Polygon EtherHiding

TL;DR: The Hacker News (2026-09-21) + Blackpoint (2026-09-18): ChainScript is a Node.js RAT delivered by ClickFix FakeCAPTCHA lures, then MSI builds (ComponentTask33 / UpdateDigital / HostShared / OrchidViolet66). C2 is EtherHiding on Polygon contract 0xf9099d0d747368cce8C10226CC9AF2bFD4DDbCF4 (selector 0x4ab7874e) plus fallback hosts shift-api-control.com:3847 / bedotiq.net:3854. Persistence name ComponentTask33Agent. Adjacent PasteSwitch HBO ClickFix is the same delivery class — not a separate campaign.

What’s New:

  • THN amplify of Blackpoint’s MSI + Polygon writeup this window; two independent sources
  • Build family is four MSI labels; process chain includes wscript → node.exe (ESCU Wscript-child analytics miss node.exe)
  • C2 mix: on-chain Polygon read + DNS/ports 3847/3854/3851 and IPs 176.65.144.127 / 176.65.144.40

Actionable Intel

ArtifactTypeATT&CKLog SourceAction
MSI builds ComponentTask33 / UpdateDigital / HostShared / OrchidViolet66 (ChainScript)Dropper / installerT1204.002 / T1218.007EDR / Sysmon 1 / MSIExec logsAlert msiexec installing those ProductName/Name strings; quarantine host; dump MSI
Parent wscript.exe / cscript.exe spawning node.exe after ClickFix pasteRAT launchT1059.007 / T1059.005Sysmon 1 / EDR process treeHunt wscript→node; ESCU Wscript Or Cscript Suspicious Child Process excludes node.exe — do not rely on it
Polygon contract 0xf9099d0d747368cce8C10226CC9AF2bFD4DDbCF4 selector 0x4ab7874eEtherHiding C2T1102 / T1071Proxy / DNS / node network / blockchain telemetryAlert Node/MSI children querying that contract or selector; treat hit as C2
C2 shift-api-control.com:3847 / bedotiq.net:3854 / kerosand.net:3847 / moweros.net:3851 / giperon.net:3847 / api-configuard.com; IPs 176.65.144.127 / 176.65.144.40RAT C2T1071 / T1571Firewall / proxy / Zeek / EDR netflowBlock+hunt egress to those host:ports; alert node.exe → raw IP on 3847/3854/3851
Persistence ComponentTask33AgentScheduled task / service nameT1053Sysmon 12/13 / schtasks / EDRHunt task/service ComponentTask33Agent; remove + isolate
Explorer → powershell/cmd/mshta with captcha/iwr+iex ClickFix strings (incl. adjacent PasteSwitch HBO lures)ClickFix user executionT1204.001 / T1059Sysmon 1 / RunMRU / EDRHunt FakeCAPTCHA clipboard paste; isolate user who ran Win+R one-liner

Detection

SourceRuleGap
Splunk ESCUPartial — Windows PowerShell FakeCAPTCHA Clipboard Execution (captcha/iwr+iex ClickFix paste); Partial — Windows MSIExec Remote Download. Wscript Or Cscript Suspicious Child Process child list excludes node.exe — misses wscript→node.No ChainScript / Polygon / ComponentTask33 analytic
ElasticPartial — Potential Fake CAPTCHA Phishing Attack (explorer→ps/cmd/mshta captcha strings) — lure onlyMisses MSI builds, EtherHiding contract, and wscript→node
SigmaPartial — Potential ClickFix Execution Pattern - Registry; Suspicious ClickFix FileFix Execution — delivery onlyNo ChainScript C2/domain rule

Hunt hint: (1) EDR: msiexec ProductName in ComponentTask33 / UpdateDigital / HostShared / OrchidViolet66. (2) Process: wscript/cscript → node.exe. (3) Net: shift-api-control.com:3847, bedotiq.net:3854, IPs 176.65.144.127/40, ports 3847/3854/3851. (4) Chain: Node reading Polygon 0xf9099d0d747368cce8C10226CC9AF2bFD4DDbCF4. (5) Persistence: ComponentTask33Agent.

Sources: Blackpoint ChainScript, The Hacker News


2. Jade Sleet / TraderTraitor — FLATROOF + ROOFDECK on Indian IT DevOps Mac

TL;DR: The Hacker News (2026-09-21) + SentinelOne (2026-09-18): Jade Sleet (aka TraderTraitor / UNC4899 / PUKCHONG) backdoored an Indian IT DevOps Mac with FLATROOF (Gaslight) at ~/Library/com.apple.iTunesCloud/SystemUpdate and ROOFDECK at ~/Library/com.apple.internal.ck/iSync and ~/Library/com.apple.appleaccountd/loginwindow. Delivery used Terraform typosquat registries registry.hashicorp-aws.com, registry.hashicorp-aws.io, registry.hashicorp-terraform.io, plus Cursor → SystemUpdate/iSync. Distinct from WaterPlum / Contagious Interview.

What’s New:

  • Victim has no crypto ties — DevOps/IT provider Mac, not the usual TraderTraitor exchange-target profile
  • Terraform registry typosquats impersonate HashiCorp AWS/Terraform module hosts
  • Cursor IDE path observed dropping SystemUpdate / iSync payloads

Actionable Intel

ArtifactTypeATT&CKLog SourceAction
Terraform registries registry.hashicorp-aws.com / registry.hashicorp-aws.io / registry.hashicorp-terraform.ioTyposquat supply-chainT1195.002 / T1608DNS / proxy / Terraform CLI logs / CIBlock those FQDNs; hunt terraform init / provider installs against them; rotate cloud keys from affected workstations
FLATROOF / Gaslight path ~/Library/com.apple.iTunesCloud/SystemUpdatemacOS backdoorT1547 / T1059macOS EDR / Unified Logs / file eventsHunt+quarantine SystemUpdate under com.apple.iTunesCloud; capture sample; isolate Mac
ROOFDECK paths ~/Library/com.apple.internal.ck/iSync and ~/Library/com.apple.appleaccountd/loginwindowmacOS backdoorT1547 / T1037macOS EDR / LaunchAgentsHunt iSync / loginwindow under those Library dirs; review LaunchAgents/Daemons
Cursor spawning writes to SystemUpdate / iSyncDev-tool executionT1059 / T1204EDR process tree (Cursor.app)Alert Cursor → unexpected ~/Library/com.apple.* writes; review trusted workspace / MCP / tasks
C2 technicais.sytes.net / storage.hubpage.cloud / grenight.com; IPs 176.97.114.232 / 45.11.59.140 / 85.137.56.245 / 85.137.56.10FLATROOF/ROOFDECK C2T1071Firewall / DNS / EDR netflowBlock+hunt; alert script interpreters to those hosts or raw IPs

Detection

SourceRuleGap
Splunk ESCUNone — verified search FLATROOF/ROOFDECK/hashicorp-awsNo Jade Sleet / Terraform typosquat analytic
ElasticPartial — Quarantine Attrib Removed by Unsigned or Untrusted Process; Partial — Persistence via Suspicious Launch Agent or Launch Daemon; Partial — Script Interpreter Connection to Non-Standard PortMay catch persistence/C2 aspects; does not name hashicorp-aws typosquats or FLATROOF paths
SigmaNone — verified searchNo emerging-threat rule for this cluster

Hunt hint: (1) DNS/proxy: registry.hashicorp-aws.com / .io / registry.hashicorp-terraform.io (not registry.terraform.io). (2) File: ~/Library/com.apple.iTunesCloud/SystemUpdate, ~/Library/com.apple.internal.ck/iSync, ~/Library/com.apple.appleaccountd/loginwindow. (3) EDR: Cursor writing those paths. (4) Egress: technicais.sytes.net, storage.hubpage.cloud, grenight.com, IPs above. (5) Do not fold this into WaterPlum hunts — different actor/malware/C2.

Sources: SentinelOne, The Hacker News


3. npm indexed-btree Runtime Malware — BTree.prototype.set

TL;DR: BleepingComputer (2026-09-20) + Checkmarx (2026-09-17): malicious npm packages led by indexed-btree (~2M weekly downloads) plus btree-core, ordered-kv-index, btree-leaderboard, priority-slot-queue, btree-range-store, btree-time-index, btree-lru-cache, neighbor-key-map, sliding-score-window, mutex-forge. Payload runs at runtime via BTree.prototype.set when key == 100bypasses npm v12 install-script blocks. C2/config on Sepolia 0xE390863Dac96a7118C71227C2b099B50cF602D31. Hunt Telegram/Slack tokens in the runtime drop.

What’s New:

  • Install-script / postinstall gates (incl. npm v12) do not see this — trigger is application set(100, …)
  • Checkmarx + BC two-source package list + Sepolia contract
  • ESCU NPM Supply Chain / Shai-Hulud stories target postinstall — miss BTree.prototype.set

Actionable Intel

ArtifactTypeATT&CKLog SourceAction
npm packages indexed-btree (~2M weekly) / btree-core / ordered-kv-index / btree-leaderboard / priority-slot-queue / btree-range-store / btree-time-index / btree-lru-cache / neighbor-key-map / sliding-score-window / mutex-forgeMalicious runtime dependencyT1195.001 / T1059.007npm/yarn/pnpm lockfiles / SBOM / CIRemove those packages; npm ls / lockfile grep; rebuild from known-good; rotate registry tokens
BTree.prototype.set with key == 100 (indexed-btree campaign)Runtime triggerT1059.007EDR / Node debug / code grepGrep node_modules and app code for prototype.set / key == 100 / key===100; treat execution as compromise
Sepolia contract 0xE390863Dac96a7118C71227C2b099B50cF602D31On-chain C2 / configT1102Proxy / Node egress / blockchain telemetryAlert Node processes querying that contract; block Sepolia RPC from build/prod if unexpected
Unexpected Telegram / Slack token use from Node after indexed-btree loadCredential theft / exfilT1552 / T1071SaaS audit / proxy / secrets scannerHunt new bot tokens / Slack xox* from CI/dev hosts; rotate

Detection

SourceRuleGap
Splunk ESCUNone — NPM Supply Chain / Shai-Hulud target postinstall; misses BTree.prototype.set runtimeWill not fire on this campaign’s runtime hook
ElasticNone — verified searchNo indexed-btree / BTree.prototype.set rule
SigmaNone — verified searchNo emerging-threat rule

Hunt hint: (1) Lockfiles/SBOM: every package name above. (2) node_modules/**/index.js containing BTree.prototype.set and 100. (3) Node egress to Sepolia 0xE390863Dac96a7118C71227C2b099B50cF602D31. (4) Rotate npm + Slack/Telegram tokens on any host that imported indexed-btree. (5) Do not close this as “npm v12 install-script block saved us.”

Sources: Checkmarx, BleepingComputer


Status Updates

  • Linux KEV CVE-2025-39682 / CVE-2026-53266 / CVE-2025-39964: KEV due was TODAY 2026-09-21 (forensic triage Yes) — confirm distro kernel trains (e.g. 5.10.245 / 5.15.194 / 6.1.154 / 6.6.108 / 6.12.49 / 6.16.9 class for CVE-2025-39964; CVE-2026-53266 trains e.g. 5.10.259 / 5.15.210 / 6.1.176 / 6.6.143 / 6.12.94; remove ebtables --snat-arp if needed as interim for CVE-2026-53266). Original brief
  • Windows CVE-2026-81963 + CVE-2026-85880: KEV due 2026-09-22 — keep ALPC/Update Stack LPE hunts. Sep 9
  • Chrome CVE-2026-87491: KEV due 2026-09-23 — Chromium ≥153.0.8010.36 class. Sep 10
  • CVE-2026-42016/CVE-2026-42018 (JFrog): KEV due 2026-09-25 — continue POST /access/api/v1/aws/token/ + token:anonymous hunts. Sep 12
  • CVE-2026-76460 (Cisco ISE) / CVE-2026-87886 (Acronis) / CVE-2026-58704 (Pixel): KEV due was 2026-09-19 — confirm patches + forensic triage closed (dummyuser ise-kong; Acronis ≥1.9.3.1021 / ≥1.8.11.638; Pixel 2026-09-05+). Sep 17 · Sep 16
  • CVE-2026-58138 (Orkes Conductor) / CVE-2026-28326 (SolarWinds ARM): No material change — keep ≥3.30.2 Conductor + ARM 2026.2.1 hunts. Original brief
  • CVE-2026-85046 (Chrome) / CVE-2026-76461 (ESA): Post-deadline — confirm ≥152.0.7977.82 and ESA fixed AsyncOS + Snort 67109/67110. Sep 5 · Sep 15
  • Brevo ClickFix / Check Point SMS CVE-2026-91843 / Unbound CVE-2026-81642 / WWLC / ParaShells / Marimo / GRAYRABBIT / Passkey / SGLang: No material change — keep prior hunts. Sep 18 · Sep 16 · Sep 14 · Sep 13
  • Check Point VPN CVE-2026-85102/CVE-2026-85103: Dutch NCSC still imminent — distinct from management CVE-2026-91843. Sep 11 · Sep 18