The SC malware appeared in at least eight locations on one compromised site and can query a smart contract through roughly 20 public gateways.