A cluster of malicious npm packages did not try to run code on install; instead, it appears to have turned package mirrors into a browser-facing trap for social engineering.
Researchers identified 24 npm packages being used as distribution points for fake Cloudflare CAPTCHA pages, showing how trusted developer infrastructure can be repurposed for social engineering.
A multi-stage loader linked to fake installers, ClickFix lures, and game-themed packages shows how attackers can hide malicious activity inside ordinary Windows workflows.
A .NET malware loader is being linked to ClickFix lures, fake download prompts, and malicious game campaigns, with blockchain-based C2 adding resilience to the campaign.
A branded download lure and a copy-paste command prompt show how ClickFix-style abuse can turn everyday software searching into user-executed malware on macOS.
WordlistLoader and SynkLoader are a reminder that criminal tooling often starts small, then hands off to stealer payloads and password theft.
A macOS campaign tied to ClickFix-style lures shows how attackers can combine social engineering, blockchain-hosted infrastructure, and mixed payloads to make cleanup and disruption more difficult.
AmnesiaStealer points to a harsher reality for defenders: on modern browsers, stealing the session can matter more than stealing the password.
A layered Windows intrusion chain blends compromised WordPress pages, user-pasted PowerShell, and driver abuse to push a reported stealer payload past endpoint defenses.
A new wave of lure pages and hand-entered PowerShell commands shows how attackers can turn ordinary verification prompts into a delivery path for defense-evasion malware.
A ClearFake campaign reportedly folds a new intermediate loader, WordlistLoader, into a fake verification flow that ends with Amatera Stealer.
A campaign tied to compromised WordPress sites is being used to push deceptive CAPTCHA prompts and a mix of ransomware, credential theft, file theft, and remote monitoring claims.
C2Looper is a July 2026 backdoor that researchers link, with caution, to ransomware-related activity and to a delivery path that may involve ClickFix chains.
A newly identified macOS infostealer uses a ClickFix-style lure and a streaming module that can let an operator interact with the victim’s browser in real time.
A counterfeit download page and a ClickFix-style lure are at the center of a macOS infostealer case that spotlights a modern threat: turning a browser login into reusable access.
AmnesiaStealer is being described as a macOS infostealer delivered through ClickFix-style lures, a reminder that on modern desktops the weakest link is often the person clicking the page.
A ClickFix-style lure can hand control to a modular loader chain and end with a persistent remote shell, turning user trust into operator access.
ErrTraffic appears to combine compromised WordPress pages, ClickFix-style social engineering, rotating delivery domains, and Polygon smart contracts into a layered route for Windows malware.
A reported MaaS campaign ties browser lures, user-driven execution, and Polygon smart contracts into a harder-to-trace delivery path.
A recent ACN CSIRT Italia advisory points to a campaign that mixes ClickFix-style social engineering with EtherHiding on BNB Smart Chain, turning a simple copy-paste prompt into a delivery path for malicious code.