ChainScript: the RAT that hides its command server inside a blockchain contract

2026-09-21T14:51:39Z•12f6c81ea938715e6adf05cb8cc3d3c50dad8178072c0b34beab6d6b1a281a3f
AI-agentsAI-securityCISA-KEVClickFixLinux-kernelNode.jsPolygonSSOaccount-takeoveractively-exploited-vulnerabilitiesautomotive-securityblockchaincloud-securitycommand-and-controlconnected-carscyber-physical-securitydata-sovereigntyjailbreaksmalwareprompt-injectionremote-access-trojan

What happened

Security Affairs feed covering a newly documented blockchain-resolving Node.js RAT, connected-vehicle exploitation, AI-agent and AI-model security risks, cloud data sovereignty concerns, actively exploited Linux kernel vulnerabilities added to CISA KEV, and account takeover through a forum vulnerability. The most urgent item is the CISA KEV update, while ChainScript and connected-car compromise represent significant malware and cyber-physical threats.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
12f6c81ea938715e6adf05cb8cc3d3c50dad8178072c0b34beab6d6b1a281a3f
Enrichment time
2026-09-21T14:51:39Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.