ClickFix malware campaigns are rapidly evolving, adopting server-side browser fingerprinting and blockchain infrastructure to evade detection. Microsoft Threat Intelligence reports that a macOS ClickFix campaign now uses a 2.5 KB JavaScript gate to profile visitors, delivering Atomic Stealer (AMOS) or MacSync only to genuine Mac environments while serving decoys to crawlers. Concurrently, the self-propagating ChainDrop npm worm has infected over 400 packages, stealing developer credentials and establishing persistence via VS Code and Claude Code.
ClickFix malware evolution
- ▪Apple released macOS 26.4 on March 24, 2026, introducing Terminal paste protections and XProtect tracing to block suspicious command execution associated with ClickFix campaigns.
- ▪Microsoft Threat Intelligence tracked a macOS ClickFix campaign that evolved from openly serving malicious commands in HTML to concealing lures behind a server-side browser-fingerprinting gate.
- ▪The SmartApeSG campaign uses ClickFix lures to trick users into running commands that launch an HTA file, which downloads an unidentified Remote Access Trojan.
- ▪The macOS ClickFix campaign utilizes social engineering to persuade users to copy and run obfuscated Terminal commands, bypassing standard macOS application trust paths like quarantine and notarization.
Browser fingerprinting evasion
- ▪The ClickFix fingerprinting gate uses a 2.5 KB JavaScript profiler to collect browser, hardware, and runtime attributes from six objects: navigator, screen, window, document, location, and console.
- ▪The ClickFix gate utilizes WebGL-derived GPU signals to distinguish genuine Apple hardware from virtualized, emulated, software-rendered, or sandboxed environments.
- ▪The ClickFix profiling script incorporates a toString() counter and a video codec check tripwire to detect browser instrumentation, developer consoles, and automated analysis frameworks.
- ▪Microsoft Threat Intelligence identified over 250 front-end domains in the macOS ClickFix campaign, many generated using dictionary words paired with the token 'file'.
Blockchain-based C2 infrastructure
- ▪The ChainDrop npm worm resolved its command-and-control infrastructure using blockchain-based resolution, allowing the adversary to reconfigure its C2 via a single Ethereum transaction on August 4, 2026.
- ▪ClickFix campaigns have utilized BNB Smart Chain smart contracts to deliver Base64-encoded JavaScript malware instructions, making them highly resistant to traditional takedown methods.
ChainDrop npm worm propagation
- ▪Once installed, the ChainDrop worm harvests cloud credentials, npm and GitHub tokens, SSH keys, and temporary credentials from GitHub Actions runner memory.
- ▪ChainDrop establishes cross-linked persistence by writing malicious task configurations to .vscode/tasks.json and session start hooks to .claude/settings.json.
- ▪The ChainDrop worm targets the opensearch-project/opensearch-js repository specifically, using OpenID Connect tokens to publish a typosquatted dependency with valid signed Sigstore provenance.
- ▪The self-propagating npm worm ChainDrop infected over 400 packages, including keyv and cacheable-request, which are collectively downloaded hundreds of millions of times each week.
Infostealer payload delivery
- ▪ClickFix campaigns targeting Windows and enterprise networks have delivered payloads including Lumma Stealer, Xworm, AsyncRAT, MintsLoader, and remote management tools.
- ▪The macOS ClickFix campaign delivers information-stealing malware, specifically MacSync and Atomic Stealer (AMOS), to harvest keychain items, browser credentials, and cryptocurrency wallets.
Story comments
Loading comments…