← Back to Feed

ClickFix on macOS: Blockchain-Powered Infostealer Hidden Inside Compromised Websites

July 16, 2026 · LevelBlue SpiderLabs · Severity: LOW

This article describes a macOS ClickFix campaign where compromised websites display fake human verification prompts. Users are instructed to open Terminal and paste code, which downloads and executes a blockchain-powered infostealer. The attack abuses user trust in common CAPTCHA processes to bypass technical defenses.

You're browsing a legitimate small business website. Before the page loads, a familiar Cloudflare box appears: "Verify you are human." It asks you to open Terminal, paste a code, and press Enter. You've seen this before. You follow the steps. The page loads normally.

Key Takeaways

  • Attackers use fake Cloudflare verification pages to trick macOS users into running commands.
  • The ClickFix technique delivers a blockchain-powered infostealer via compromised legitimate websites.
  • Users should avoid pasting unknown commands into Terminal, even from familiar-looking captcha prompts.
☕ Buy a Coffee