← Back to Feed

ClickFix campaign abuses Deno runtime for infostealer delivery

August 11, 2026 · Sophos Threat Research · Severity: MEDIUM

Lures on compromised WordPress sites led to installation of Deno and a Python-based infostealerCategories: Threat ResearchTags: clickfix, Deno, WordPress

Key Takeaways

  • A ClickFix campaign abuses the Deno runtime for infostealer delivery.
  • Lures on compromised WordPress sites led to installation of Deno and a Python-based infostealer.
  • The attack chain uses ClickFix lures hosted on hacked WordPress sites to drop malware.
☕ Buy a Coffee