Cyber Threat Brief — September 21 2026
1. ChainScript Node.js RAT — ClickFix + Polygon EtherHiding
TL;DR: The Hacker News (2026-09-21) + Blackpoint (2026-09-18): ChainScript is a Node.js RAT delivered by ClickFix FakeCAPTCHA lures, then MSI builds (ComponentTask33 / UpdateDigital / HostShared / OrchidViolet66). C2 is EtherHiding on Polygon contract 0xf9099d0d747368cce8C10226CC9AF2bFD4DDbCF4 (selector 0x4ab7874e) plus fallback hosts shift-api-control.com:3847 / bedotiq.net:3854. Persistence name ComponentTask33Agent. Adjacent PasteSwitch HBO ClickFix is the same delivery class — not a separate campaign.
What’s New:
- THN amplify of Blackpoint’s MSI + Polygon writeup this window; two independent sources
- Build family is four MSI labels; process chain includes wscript → node.exe (ESCU Wscript-child analytics miss
node.exe) - C2 mix: on-chain Polygon read + DNS/ports 3847/3854/3851 and IPs 176.65.144.127 / 176.65.144.40
Actionable Intel
| Artifact | Type | ATT&CK | Log Source | Action |
|---|---|---|---|---|
| MSI builds ComponentTask33 / UpdateDigital / HostShared / OrchidViolet66 (ChainScript) | Dropper / installer | T1204.002 / T1218.007 | EDR / Sysmon 1 / MSIExec logs | Alert msiexec installing those ProductName/Name strings; quarantine host; dump MSI |
| Parent wscript.exe / cscript.exe spawning node.exe after ClickFix paste | RAT launch | T1059.007 / T1059.005 | Sysmon 1 / EDR process tree | Hunt wscript→node; ESCU Wscript Or Cscript Suspicious Child Process excludes node.exe — do not rely on it |
Polygon contract 0xf9099d0d747368cce8C10226CC9AF2bFD4DDbCF4 selector 0x4ab7874e | EtherHiding C2 | T1102 / T1071 | Proxy / DNS / node network / blockchain telemetry | Alert Node/MSI children querying that contract or selector; treat hit as C2 |
C2 shift-api-control.com:3847 / bedotiq.net:3854 / kerosand.net:3847 / moweros.net:3851 / giperon.net:3847 / api-configuard.com; IPs 176.65.144.127 / 176.65.144.40 | RAT C2 | T1071 / T1571 | Firewall / proxy / Zeek / EDR netflow | Block+hunt egress to those host:ports; alert node.exe → raw IP on 3847/3854/3851 |
| Persistence ComponentTask33Agent | Scheduled task / service name | T1053 | Sysmon 12/13 / schtasks / EDR | Hunt task/service ComponentTask33Agent; remove + isolate |
Explorer → powershell/cmd/mshta with captcha/iwr+iex ClickFix strings (incl. adjacent PasteSwitch HBO lures) | ClickFix user execution | T1204.001 / T1059 | Sysmon 1 / RunMRU / EDR | Hunt FakeCAPTCHA clipboard paste; isolate user who ran Win+R one-liner |
Detection
| Source | Rule | Gap |
|---|---|---|
| Splunk ESCU | Partial — Windows PowerShell FakeCAPTCHA Clipboard Execution (captcha/iwr+iex ClickFix paste); Partial — Windows MSIExec Remote Download. Wscript Or Cscript Suspicious Child Process child list excludes node.exe — misses wscript→node. | No ChainScript / Polygon / ComponentTask33 analytic |
| Elastic | Partial — Potential Fake CAPTCHA Phishing Attack (explorer→ps/cmd/mshta captcha strings) — lure only | Misses MSI builds, EtherHiding contract, and wscript→node |
| Sigma | Partial — Potential ClickFix Execution Pattern - Registry; Suspicious ClickFix FileFix Execution — delivery only | No ChainScript C2/domain rule |
Hunt hint: (1) EDR: msiexec ProductName in ComponentTask33 / UpdateDigital / HostShared / OrchidViolet66. (2) Process: wscript/cscript → node.exe. (3) Net: shift-api-control.com:3847, bedotiq.net:3854, IPs 176.65.144.127/40, ports 3847/3854/3851. (4) Chain: Node reading Polygon 0xf9099d0d747368cce8C10226CC9AF2bFD4DDbCF4. (5) Persistence: ComponentTask33Agent.
Sources: Blackpoint ChainScript, The Hacker News
2. Jade Sleet / TraderTraitor — FLATROOF + ROOFDECK on Indian IT DevOps Mac
TL;DR: The Hacker News (2026-09-21) + SentinelOne (2026-09-18): Jade Sleet (aka TraderTraitor / UNC4899 / PUKCHONG) backdoored an Indian IT DevOps Mac with FLATROOF (Gaslight) at ~/Library/com.apple.iTunesCloud/SystemUpdate and ROOFDECK at ~/Library/com.apple.internal.ck/iSync and ~/Library/com.apple.appleaccountd/loginwindow. Delivery used Terraform typosquat registries registry.hashicorp-aws.com, registry.hashicorp-aws.io, registry.hashicorp-terraform.io, plus Cursor → SystemUpdate/iSync. Distinct from WaterPlum / Contagious Interview.
What’s New:
- Victim has no crypto ties — DevOps/IT provider Mac, not the usual TraderTraitor exchange-target profile
- Terraform registry typosquats impersonate HashiCorp AWS/Terraform module hosts
- Cursor IDE path observed dropping SystemUpdate / iSync payloads
Actionable Intel
| Artifact | Type | ATT&CK | Log Source | Action |
|---|---|---|---|---|
Terraform registries registry.hashicorp-aws.com / registry.hashicorp-aws.io / registry.hashicorp-terraform.io | Typosquat supply-chain | T1195.002 / T1608 | DNS / proxy / Terraform CLI logs / CI | Block those FQDNs; hunt terraform init / provider installs against them; rotate cloud keys from affected workstations |
FLATROOF / Gaslight path ~/Library/com.apple.iTunesCloud/SystemUpdate | macOS backdoor | T1547 / T1059 | macOS EDR / Unified Logs / file events | Hunt+quarantine SystemUpdate under com.apple.iTunesCloud; capture sample; isolate Mac |
ROOFDECK paths ~/Library/com.apple.internal.ck/iSync and ~/Library/com.apple.appleaccountd/loginwindow | macOS backdoor | T1547 / T1037 | macOS EDR / LaunchAgents | Hunt iSync / loginwindow under those Library dirs; review LaunchAgents/Daemons |
| Cursor spawning writes to SystemUpdate / iSync | Dev-tool execution | T1059 / T1204 | EDR process tree (Cursor.app) | Alert Cursor → unexpected ~/Library/com.apple.* writes; review trusted workspace / MCP / tasks |
C2 technicais.sytes.net / storage.hubpage.cloud / grenight.com; IPs 176.97.114.232 / 45.11.59.140 / 85.137.56.245 / 85.137.56.10 | FLATROOF/ROOFDECK C2 | T1071 | Firewall / DNS / EDR netflow | Block+hunt; alert script interpreters to those hosts or raw IPs |
Detection
| Source | Rule | Gap |
|---|---|---|
| Splunk ESCU | None — verified search FLATROOF/ROOFDECK/hashicorp-aws | No Jade Sleet / Terraform typosquat analytic |
| Elastic | Partial — Quarantine Attrib Removed by Unsigned or Untrusted Process; Partial — Persistence via Suspicious Launch Agent or Launch Daemon; Partial — Script Interpreter Connection to Non-Standard Port | May catch persistence/C2 aspects; does not name hashicorp-aws typosquats or FLATROOF paths |
| Sigma | None — verified search | No emerging-threat rule for this cluster |
Hunt hint: (1) DNS/proxy: registry.hashicorp-aws.com / .io / registry.hashicorp-terraform.io (not registry.terraform.io). (2) File: ~/Library/com.apple.iTunesCloud/SystemUpdate, ~/Library/com.apple.internal.ck/iSync, ~/Library/com.apple.appleaccountd/loginwindow. (3) EDR: Cursor writing those paths. (4) Egress: technicais.sytes.net, storage.hubpage.cloud, grenight.com, IPs above. (5) Do not fold this into WaterPlum hunts — different actor/malware/C2.
Sources: SentinelOne, The Hacker News
3. npm indexed-btree Runtime Malware — BTree.prototype.set
TL;DR: BleepingComputer (2026-09-20) + Checkmarx (2026-09-17): malicious npm packages led by indexed-btree (~2M weekly downloads) plus btree-core, ordered-kv-index, btree-leaderboard, priority-slot-queue, btree-range-store, btree-time-index, btree-lru-cache, neighbor-key-map, sliding-score-window, mutex-forge. Payload runs at runtime via BTree.prototype.set when key == 100 — bypasses npm v12 install-script blocks. C2/config on Sepolia 0xE390863Dac96a7118C71227C2b099B50cF602D31. Hunt Telegram/Slack tokens in the runtime drop.
What’s New:
- Install-script / postinstall gates (incl. npm v12) do not see this — trigger is application
set(100, …) - Checkmarx + BC two-source package list + Sepolia contract
- ESCU NPM Supply Chain / Shai-Hulud stories target postinstall — miss
BTree.prototype.set
Actionable Intel
| Artifact | Type | ATT&CK | Log Source | Action |
|---|---|---|---|---|
npm packages indexed-btree (~2M weekly) / btree-core / ordered-kv-index / btree-leaderboard / priority-slot-queue / btree-range-store / btree-time-index / btree-lru-cache / neighbor-key-map / sliding-score-window / mutex-forge | Malicious runtime dependency | T1195.001 / T1059.007 | npm/yarn/pnpm lockfiles / SBOM / CI | Remove those packages; npm ls / lockfile grep; rebuild from known-good; rotate registry tokens |
BTree.prototype.set with key == 100 (indexed-btree campaign) | Runtime trigger | T1059.007 | EDR / Node debug / code grep | Grep node_modules and app code for prototype.set / key == 100 / key===100; treat execution as compromise |
Sepolia contract 0xE390863Dac96a7118C71227C2b099B50cF602D31 | On-chain C2 / config | T1102 | Proxy / Node egress / blockchain telemetry | Alert Node processes querying that contract; block Sepolia RPC from build/prod if unexpected |
Unexpected Telegram / Slack token use from Node after indexed-btree load | Credential theft / exfil | T1552 / T1071 | SaaS audit / proxy / secrets scanner | Hunt new bot tokens / Slack xox* from CI/dev hosts; rotate |
Detection
| Source | Rule | Gap |
|---|---|---|
| Splunk ESCU | None — NPM Supply Chain / Shai-Hulud target postinstall; misses BTree.prototype.set runtime | Will not fire on this campaign’s runtime hook |
| Elastic | None — verified search | No indexed-btree / BTree.prototype.set rule |
| Sigma | None — verified search | No emerging-threat rule |
Hunt hint: (1) Lockfiles/SBOM: every package name above. (2) node_modules/**/index.js containing BTree.prototype.set and 100. (3) Node egress to Sepolia 0xE390863Dac96a7118C71227C2b099B50cF602D31. (4) Rotate npm + Slack/Telegram tokens on any host that imported indexed-btree. (5) Do not close this as “npm v12 install-script block saved us.”
Sources: Checkmarx, BleepingComputer
Status Updates
- Linux KEV CVE-2025-39682 / CVE-2026-53266 / CVE-2025-39964: KEV due was TODAY 2026-09-21 (forensic triage Yes) — confirm distro kernel trains (e.g. 5.10.245 / 5.15.194 / 6.1.154 / 6.6.108 / 6.12.49 / 6.16.9 class for CVE-2025-39964; CVE-2026-53266 trains e.g. 5.10.259 / 5.15.210 / 6.1.176 / 6.6.143 / 6.12.94; remove ebtables
--snat-arpif needed as interim for CVE-2026-53266). Original brief - Windows CVE-2026-81963 + CVE-2026-85880: KEV due 2026-09-22 — keep ALPC/Update Stack LPE hunts. Sep 9
- Chrome CVE-2026-87491: KEV due 2026-09-23 — Chromium ≥153.0.8010.36 class. Sep 10
- CVE-2026-42016/CVE-2026-42018 (JFrog): KEV due 2026-09-25 — continue
POST /access/api/v1/aws/token/+token:anonymoushunts. Sep 12 - CVE-2026-76460 (Cisco ISE) / CVE-2026-87886 (Acronis) / CVE-2026-58704 (Pixel): KEV due was 2026-09-19 — confirm patches + forensic triage closed (
dummyuserise-kong; Acronis ≥1.9.3.1021 / ≥1.8.11.638; Pixel 2026-09-05+). Sep 17 · Sep 16 - CVE-2026-58138 (Orkes Conductor) / CVE-2026-28326 (SolarWinds ARM): No material change — keep ≥3.30.2 Conductor + ARM 2026.2.1 hunts. Original brief
- CVE-2026-85046 (Chrome) / CVE-2026-76461 (ESA): Post-deadline — confirm ≥152.0.7977.82 and ESA fixed AsyncOS + Snort 67109/67110. Sep 5 · Sep 15
- Brevo ClickFix / Check Point SMS CVE-2026-91843 / Unbound CVE-2026-81642 / WWLC / ParaShells / Marimo / GRAYRABBIT / Passkey / SGLang: No material change — keep prior hunts. Sep 18 · Sep 16 · Sep 14 · Sep 13
- Check Point VPN CVE-2026-85102/CVE-2026-85103: Dutch NCSC still imminent — distinct from management CVE-2026-91843. Sep 11 · Sep 18