Geo News
Community curated by people like you
LatestAICryptoHealthWorld AffairsUS Politics
ClickFix Malware Campaigns Evolve with Blockchain Infrastructure and Browser Fingerprinting to Evade Detection
00

ClickFix Malware Campaigns Evolve with Blockchain Infrastructure and Browser Fingerprinting to Evade Detection

Aug 7, 2026

ClickFix malware campaigns are rapidly evolving, adopting server-side browser fingerprinting and blockchain infrastructure to evade detection. Microsoft Threat Intelligence reports that a macOS ClickFix campaign now uses a 2.5 KB JavaScript gate to profile visitors, delivering Atomic Stealer (AMOS) or MacSync only to genuine Mac environments while serving decoys to crawlers. Concurrently, the self-propagating ChainDrop npm worm has infected over 400 packages, stealing developer credentials and establishing persistence via VS Code and Claude Code.

ClickFix malware evolution

  • ▪Apple released macOS 26.4 on March 24, 2026, introducing Terminal paste protections and XProtect tracing to block suspicious command execution associated with ClickFix campaigns.
  • ▪Microsoft Threat Intelligence tracked a macOS ClickFix campaign that evolved from openly serving malicious commands in HTML to concealing lures behind a server-side browser-fingerprinting gate.
  • ▪The SmartApeSG campaign uses ClickFix lures to trick users into running commands that launch an HTA file, which downloads an unidentified Remote Access Trojan.
  • ▪The macOS ClickFix campaign utilizes social engineering to persuade users to copy and run obfuscated Terminal commands, bypassing standard macOS application trust paths like quarantine and notarization.

Browser fingerprinting evasion

  • ▪The ClickFix fingerprinting gate uses a 2.5 KB JavaScript profiler to collect browser, hardware, and runtime attributes from six objects: navigator, screen, window, document, location, and console.
  • ▪The ClickFix gate utilizes WebGL-derived GPU signals to distinguish genuine Apple hardware from virtualized, emulated, software-rendered, or sandboxed environments.
  • ▪The ClickFix profiling script incorporates a toString() counter and a video codec check tripwire to detect browser instrumentation, developer consoles, and automated analysis frameworks.
  • ▪Microsoft Threat Intelligence identified over 250 front-end domains in the macOS ClickFix campaign, many generated using dictionary words paired with the token 'file'.

Blockchain-based C2 infrastructure

  • ▪The ChainDrop npm worm resolved its command-and-control infrastructure using blockchain-based resolution, allowing the adversary to reconfigure its C2 via a single Ethereum transaction on August 4, 2026.
  • ▪ClickFix campaigns have utilized BNB Smart Chain smart contracts to deliver Base64-encoded JavaScript malware instructions, making them highly resistant to traditional takedown methods.

ChainDrop npm worm propagation

  • ▪Once installed, the ChainDrop worm harvests cloud credentials, npm and GitHub tokens, SSH keys, and temporary credentials from GitHub Actions runner memory.
  • ▪ChainDrop establishes cross-linked persistence by writing malicious task configurations to .vscode/tasks.json and session start hooks to .claude/settings.json.
  • ▪The ChainDrop worm targets the opensearch-project/opensearch-js repository specifically, using OpenID Connect tokens to publish a typosquatted dependency with valid signed Sigstore provenance.
  • ▪The self-propagating npm worm ChainDrop infected over 400 packages, including keyv and cacheable-request, which are collectively downloaded hundreds of millions of times each week.

Infostealer payload delivery

  • ▪ClickFix campaigns targeting Windows and enterprise networks have delivered payloads including Lumma Stealer, Xworm, AsyncRAT, MintsLoader, and remote management tools.
  • ▪The macOS ClickFix campaign delivers information-stealing malware, specifically MacSync and Atomic Stealer (AMOS), to harvest keychain items, browser credentials, and cryptocurrency wallets.

6 sources

Socprime
SmartApeSG ClickFix Campaign Delivers Unknown RAT
View source article
Crypto
Microsoft flags ClickFix malware using BNB Chain to fetch attack instructions
View source article
Thehackernews
Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures
View source article
Microsoft
From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide | Microsoft Security Blog
View source article
Cyberkendra
Mac Malware Checks Your GPU Before Showing Its Lure
View source article

Story comments

Loading comments…

Topics

Software supply chain attacksSmart contracts