← Back to Feed
ClickFix on macOS: Blockchain-Powered Infostealer Hidden Inside Compromised Websites
July 16, 2026 · LevelBlue SpiderLabs · Severity: LOW
This article describes a macOS ClickFix campaign where compromised websites display fake human verification prompts. Users are instructed to open Terminal and paste code, which downloads and executes a blockchain-powered infostealer. The attack abuses user trust in common CAPTCHA processes to bypass technical defenses.
You're browsing a legitimate small business website. Before the page loads, a familiar Cloudflare box appears: "Verify you are human." It asks you to open Terminal, paste a code, and press Enter. You've seen this before. You follow the steps. The page loads normally.
Key Takeaways
- Attackers use fake Cloudflare verification pages to trick macOS users into running commands.
- The ClickFix technique delivers a blockchain-powered infostealer via compromised legitimate websites.
- Users should avoid pasting unknown commands into Terminal, even from familiar-looking captcha prompts.