logo

ClickFix campaign abuses Deno runtime for infostealer delivery

ID: b5a998f1-9fb0-55ca-9d50-5a06b7e44ef3

STIX ID: report--b5a998f1-9fb0-55ca-9d50-5a06b7e44ef3

Feed Name: Sophos Blogs

Threat Score
75/100

Date Published: 2026-08-11

Date Updated: 2026-08-12

...
...

CTU researchers investigated a June 2026 ClickFix campaign in which over 500 compromised WordPress sites delivered Cloudflare-themed lures that convinced users to run a PowerShell command; an MSI installer then used winget to install the legitimately signed Deno runtime, which fetched remote JavaScript to orchestrate follow-on activity including a Python infostealer, system reconnaissance, and persistence via registry Run keys and scheduled tasks, with identified C2 domains and an IP address provided as indicators.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.