Find notable cyber news and cases, enriched with sources, timelines, and signals.

ClickFix malicious JavaScript browser crypto-skimmer activity

Malware Activity
First reported
Last updated
Happening score
H score 16
1 unique sources, 1 articles

Summary

Hide ▲

A ClickFix payload now uses malicious JavaScript inside browser sessions to steal cryptocurrency deposits and copied addresses. The code is delivered through the Google Visualization API and a public Google Sheets document, then injected into sessions on two cryptocurrency trading sites. It replaces deposit addresses, alters transaction amounts, and can override browser fetch behavior to divert funds. The browser-based design and repeated reloading make the skimming harder to spot and increase theft risk.

Related Happenings

ClickFix browser-injection crypto-fraud campaign

Campaign
H score19 First: 09.09.2026 16:45 Last: 09.09.2026 16:45 Sources 1

How related: Talos found the material on Telegram, the cybercrime forum DarkForums and text-sharing sites, with waves of messages sent at least twice a month.

About this happening: The ClickFix operation has shifted into browser-side JavaScript injection, expanding its fraud reach and raising the risk of cryptocurrency theft during live trading s...

JSCeal malware activity

Malware Activity
H score29 First: 07.09.2026 10:53 Last: 07.09.2026 10:53 Sources 1

About this happening: JSCeal is a compiled V8 JavaScript malware that now stands out for credential harvesting, session replay, and traffic interception against browser data. The ma...

ClickFix AmnesiaStealer distribution campaign targeting mac users

Campaign
H score22 First: 14.08.2026 13:45 Last: 14.08.2026 13:45 Sources 1

About this happening: A ClickFix campaign is distributing AmnesiaStealer to macOS users through a counterfeit GitHub "Download for macOS" page and a copy-and-paste command that launches...

Latest development: 16.08.2026 18:07

Jamf described AmnesiaStealer's stream_module and remote_stream commands, which copy a victim's Chromium profile into a hidden headless browser and open WebSocket and Chrome DevTools Protocol channels through webSocketDebuggerUrl. The operator can issue navigation and mouse commands, receive live screencasts, and export or import cookies to operate online portals inside the victim's authenticated sessions on Google Chrome, Microsoft Edge, Vivaldi, Arc, Opera, Brave, and Chromium.

Google DoubleClick malspam campaign delivering DesckVB RAT

Campaign
H score33 First: 03.06.2026 19:29 Last: 03.06.2026 19:29 Sources 1

About this happening: A new malspam campaign is abusing Google's DoubleClick redirect path to evade detection and deliver DesckVB RAT, putting users and organizations at risk of malware inf...

Venom Stealer MaaS continuous credential theft and exfiltration

Malware Activity
H score29 First: 01.04.2026 16:30 Last: 01.04.2026 16:30 Sources 1

About this happening: The Venom Stealer malware-as-a-service platform has been identified as a credential-theft threat that keeps exfiltrating data after infection, extending the window for...

Timeline

  1. 09.09.2026 16:45 2 articles · 1h ago

    ClickFix shifts into browser-based crypto skimming

    Initial Disclosure

    Cisco Talos found that the ClickFix campaign shifted from lures that made victims paste JavaScript into Chrome's navigation bar to malicious JavaScript injected into browser sessions on two cryptocurrency trading sites. The operators used the Google Visualization API to retrieve obfuscated code from a public Google Sheets document, then changed tactics in March 2026 by adding the API and from mid-April by telling victims to install the Tampermonkey browser extension before adding a script. Talos said the lures posed as leaked vulnerability reports about non-existent API flaws at cryptocurrency swap services and that the scripts replaced deposit addresses, altered transaction amounts, overrode fetch responses, and swapped clipboard data; the group also survived disruption attempts after Talos alerted Google and the targeted sites in April, with replacement Google documents still live on August 11. Talos identified 49 Bitcoin addresses across the campaign, and one decoded set of wallets covering April to late June received victim funds totaling 0.159 BTC, about $10,000 at early August valuations.

    Show sources