ChainScript: the RAT that hides its command server inside a blockchain contract
2026-09-21T14:51:39Z•12f6c81ea938715e6adf05cb8cc3d3c50dad8178072c0b34beab6d6b1a281a3f
AI-agentsAI-securityCISA-KEVClickFixLinux-kernelNode.jsPolygonSSOaccount-takeoveractively-exploited-vulnerabilitiesautomotive-securityblockchaincloud-securitycommand-and-controlconnected-carscyber-physical-securitydata-sovereigntyjailbreaksmalwareprompt-injectionremote-access-trojan
What happened
Security Affairs feed covering a newly documented blockchain-resolving Node.js RAT, connected-vehicle exploitation, AI-agent and AI-model security risks, cloud data sovereignty concerns, actively exploited Linux kernel vulnerabilities added to CISA KEV, and account takeover through a forum vulnerability. The most urgent item is the CISA KEV update, while ChainScript and connected-car compromise represent significant malware and cyber-physical threats.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 12f6c81ea938715e6adf05cb8cc3d3c50dad8178072c0b34beab6d6b1a281a3f
- Enrichment time
- 2026-09-21T14:51:39Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.