Sitemap

Threat Intelligence | Analysis of Token Vesting Phishing Poisoning

6 min readFeb 2, 2026

--

Press enter or click to view image in full size

Background

Recently, the Chainbase Lab detected and captured a phishing email campaign disguised as an “audit/compliance confirmation.” After desensitizing the relevant malicious samples, Chainbase shared them with the SlowMist security team. The two parties jointly conducted an investigation and analysis of the malicious samples.

The attackers initially lured recipients into replying by asking them to “confirm the company’s legal English name,” and then followed up with messages using pretexts such as “FY2025 External Audit” and “Token Vesting Confirmation — submission deadline,” delivering malicious Word/PDF attachments. Through social engineering tactics, victims were induced to open the attachments and follow the instructions, ultimately leading to the theft of credentials or sensitive data.

Press enter or click to view image in full size
Press enter or click to view image in full size

Malware Analysis

The captured campaign is a targeted attack against the macOS platform, combining social engineering techniques with multi-stage fileless payloads (with certain stages primarily executed in memory or existing as temporary files). The attackers leveraged the persuasive business pretext of “audit and compliance,” using a disguised AppleScript as the initial infection vector. By tricking users into granting permissions and attempting to bypass macOS TCC protections, the attackers ultimately established a Node.js–based remote control environment on the victim’s machine.

Based on the characteristics of the sample files, the email attachment was named “Confirmation_Token_Vesting.docx.scpt.” Despite appearing to be a DOCX document via a double extension, it was in fact an AppleScript file (.scpt).

Press enter or click to view image in full size

After decoding the script content, it was found that the first-stage (initial) AppleScript was primarily responsible for delivering subsequent malicious code.

Press enter or click to view image in full size
  1. Opens the macOS System Settings and navigates to Software Update, misleading the user into believing that the system is undergoing a software update or repair process.
  2. Collects system information, including CPU architecture (Intel or Apple Silicon), macOS version, and system language, and sends this data to a remote server so it can determine which payload to deliver.
  3. Downloads and executes a script from the suspicious domain sevrrhst[.]com, and then cleans up traces of the activity.
Press enter or click to view image in full size

After decoding and analyzing the downloaded script, it was confirmed to be a malicious AppleScript with capabilities for information theft, privilege bypass, and remote command execution.

Press enter or click to view image in full size

Primary Behaviors of the Malicious Script:

Fake Progress Bar

The script first displays a forged progress bar window, claiming to be “fixing system update issues” or “resolving document viewer problems.”

Phishing Pop-up Windows

While the progress bar is running, it presents highly realistic system permission/password prompt dialogs (disguised as macOS system settings alerts and incorporating Google avatar elements):

  • Password Theft: When the user enters a password and clicks “OK,” the script invokes the dscl command to verify whether the password is correct.
  • Exfiltration to Server: Once the password is successfully validated, the script immediately uses curl to Base64-encode the collected username and password and exfiltrate them to the server sevrrhst[.]com.

Bypassing TCC Restrictions

The script attempts to tamper with macOS’s TCC (Transparency, Consent, and Control) privacy database:

Directory Masquerading: It tries to evade system protection mechanisms by renaming TCC database–related directories (e.g., com.apple.TCC).

Silent Authorization: It directly injects SQL statements into the database to silently grant permissions — without the user’s awareness — to itself as well as to Bash, Terminal, and script editors, including:

File Access Permissions: Downloads, Documents, Desktop, external disks, and more.

Privacy / Control Permissions: Camera, screen recording, keyboard event monitoring, Accessibility, and related capabilities.

Establishing a Persistent Backdoor

Downloads encrypted data named origin, decodes it, drops it to disk, and executes it.

Establishes a communication channel with the command-and-control server to receive remote commands, which are then executed via Bash.

Press enter or click to view image in full size

After preparing a Node.js runtime environment, it issues another request (req=skip) to retrieve the core script index.js and launches it.

Press enter or click to view image in full size

The index.js script collects system version, CPU, disk, network, and process information and reports it back to the server. Based on this data, the server delivers additional script code, which the malware dynamically executes via eval, enabling ongoing functional expansion and persistence.

Malicious Domain Analysis

Threat intelligence platform checks show that the domain sevrrhst[.]com was registered on January 23, 2026. It uses a low-cost free TLS certificate and exhibits typical “fast-flux / throwaway infrastructure” characteristics.The domain resolves to the IP address 88.119.171.59.

Press enter or click to view image in full size

Further investigation reveals that this IP is also associated with more than 10 similar malicious domains, including tattomc[.]com and stomcs[.]com, indicating reuse of attacker infrastructure.

Press enter or click to view image in full size
Press enter or click to view image in full size

Summary

This sample is not a simple information stealer, but rather a multi-stage intrusion chain:

  • It first uses AppleScript to lure users into interaction, steal credentials, and attempt privilege escalation.
  • It then leverages Node.js (index.js) to establish a dynamically extensible remote command execution framework.

Key characteristics include:

  • Abuse of legitimate system tools
  • Dynamic delivery and execution of attacker-controlled code

These behaviors make the threat difficult to detect using static signature-based detection mechanisms.

Recommendations:

  1. If a user has mistakenly opened and executed the malicious attachment/script or entered their system password, immediately disconnect the affected system from the network.
  2. Affected users should execute the following command to reset the TCC database and revoke unauthorized permissions granted by the malware.
  3. Remove malicious processes, and terminate any malicious Node.js processes running from hidden directories.

About Chainbase Labs

Chainbase Labs is redefining data as a financial primitive for the AI era. The Hyperdata Network converts fragmented onchain signals into structured, verifiable data that powers AI models, autonomous agents, and decentralized applications.

To date, the Chainbase Network has indexed over 200 blockchains, processed more than 500 billion data calls, and supports a community of more than 35,000 developers. Over 10,000 projects actively use Chainbase across a wide range of use cases, including security infrastructure, L2 explorers, agent protocols, and onchain analytics.

IOC

filename: Confirmation_Token_Vesting.docx.scpt

SHA256:

3e4d35903c51db3da8d4bd77491b5c181b7361aaf152609d03a1e2bb86faee43

filename: env_arm.zip

SHA256:

f9e0376114c57d659025ceb46f1ef48aa80b8af5909b2de0cf80e88040fef345

filename: index.js

SHA256:

0f1e457488fe799dee7ace7e1bc2df4c1793245f334a4298035652ebeb249414

URL:

https://sevrrhst[.]com/css/controller.php

https://sevrrhst[.]com/inc/register.php

C2: sevrrhst[.]com

IP: 88.119.171.59

About SlowMist

SlowMist is a threat intelligence firm focused on blockchain security, established in January 2018. The firm was started by a team with over ten years of network security experience to become a global force. Our goal is to make the blockchain ecosystem as secure as possible for everyone. We are now a renowned international blockchain security firm that has worked on various well-known projects such as HashKey Exchange, OSL, MEEX, BGE, BTCBOX, Bitget, BHEX.SG, OKX, Binance, HTX, Amber Group, Crypto.com, etc.

SlowMist offers a variety of services that include but are not limited to security audits, threat information, defense deployment, security consultants, and other security-related services. We also offer AML (Anti-money laundering) software, MistEye (Security Monitoring), SlowMist Hacked (Crypto hack archives), FireWall.x (Smart contract firewall) and other SaaS products. We have partnerships with domestic and international firms such as Akamai, BitDefender, RC², TianJi Partners, IPIP, etc. Our extensive work in cryptocurrency crime investigations has been cited by international organizations and government bodies, including the United Nations Security Council and the United Nations Office on Drugs and Crime.

By delivering a comprehensive security solution customized to individual projects, we can identify risks and prevent them from occurring. Our team was able to find and publish several high-risk blockchain security flaws. By doing so, we could spread awareness and raise the security standards in the blockchain ecosystem.

--

--

SlowMist
SlowMist

Written by SlowMist

SlowMist is a Blockchain security firm established in 2018, providing services such as security audits, security consultants, red teaming, and more.