Known malicious kitcriticalphishing
ClearFake / ClickFix — Everything.exe sideload chain, injected loader and TDS hosts
family: clearfake-everything-sideload-2026-09
Browser-side stage of the ClickFix chain that ends in a signed Everything.exe sideloading a trojanized WindowsCodecs.dll (see the C2-host row in this family). Compromised websites load check.first-node.rocks/api/script.js?t=<site token>, which reads a smart contract through public Polygon RPC endpoints (EtherHiding) and hands off to a traffic-distribution server on a rotating subdomain of blinqueofficial.com (cup., barn., earl.). The TDS answers /api/?a=tds_cfg, serves a large fake Cloudflare verification script (cf.js), and polls /api/?a=check_dl while waiting for the visitor to paste and run the staged PowerShell command.
Anchors
SMQL queryrun
contacted_host:first-node.rocks OR contacted_host:*.first-node.rocks OR contacted_host:*.blinqueofficial.comProvenance
Added: 2026-09-25 14:24
first-node.rocks is anchored whole, apex included: it was registered for this operation. blinqueofficial.com is an older domain whose subdomains are used as TDS hosts, so only its subdomains are anchored, never the apex. The Polygon RPC endpoints are public infrastructure and must not be anchored. A sighting is the compromised site that injected the loader, which is the page to report.