As cited
Copy frozen at (site build).
threat intel
ClickFix campaign abuses Deno runtime for infostealer delivery
Security researchers identified a ClickFix campaign that leverages compromised WordPress sites to socially engineer users into installing Deno runtime, which then executes a Python-based infostealer. The attack chain abuses Deno's legitimacy as a development tool to evade detection and establish persistence on infected systems.
Why it matters: Organizations and users who visit compromised WordPress sites face credential and data theft; practitioners should monitor for suspicious Deno installations and review endpoint controls for Python execution in unexpected contexts.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
ClickFix campaign abuses Deno runtime for infostealer delivery
Security researchers identified a ClickFix campaign that leverages compromised WordPress sites to socially engineer users into installing Deno runtime, which then executes a Python-based infostealer. The attack chain abuses Deno's legitimacy as a development tool to evade detection and establish persistence on infected systems.
Why it matters: Organizations and users who visit compromised WordPress sites face credential and data theft; practitioners should monitor for suspicious Deno installations and review endpoint controls for Python execution in unexpected contexts.
- Source published
- First seen by Cybersecurity Tracker