logo

ClickFix on macOS: Blockchain-Powered Infostealer Hidden Inside Compromised Websites

ID: 75f9d678-e8f9-5e8c-b21d-a10c1d6abb76

STIX ID: report--75f9d678-e8f9-5e8c-b21d-a10c1d6abb76

Feed Name: LevelBlue SpiderLabs Blog

Threat Score
75/100

Date Published: 2026-07-16

Date Updated: 2026-07-17

Author: Rodel Mendrez

...
...

A widespread ClickFix campaign compromises hundreds of WordPress sites to serve a full-screen iframe overlay that coerces macOS visitors into pasting a clipboard command; the command fetches an in-memory gzip/Base64 dropper that runs an osascript-driven infostealer to harvest Keychain items, browser profiles, SSH keys and exfiltrate data to genomicsforge.com, while the C2 URL is stored in a Polygon smart contract to resist takedowns — the report includes IOCs and mitigation steps.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.