Global ClickFix Campaign on WordPress Sites Actively Blocks AI Crawlers
cyb3rops · x · 2026-08-08
Security researchers uncovered a ClickFix campaign targeting compromised WordPress sites globally. Attackers injected polymorphic JavaScript that filters bot-like User-Agents, specifically including headless browsers, ChatGPT, and Anthropic, to evade detection.
The loader removes its own <script> tag, XOR-obfuscates telemetry, and POSTs data to a C2 server. The server returns XOR-decoded responses executed via indirect eval(), allowing arbitrary JavaScript execution in the victim's browser. 44 affected sites across 15 countries have been identified so far.
More from Safety
- Black Hat's Scariest Talk: AI Agents Are More Dangerous Than Tigers — JeffLadish · 2026-08-08
- API Model Security Controls Failing: Third-Party Audits Needed — BlancheMinerva · 2026-08-08
- AI Safety Experts Question Effectiveness of Built-in Guardrails and External Monitoring — BlancheMinerva · 2026-08-08
- AI Agents Invent Secret Languages: Path Prefixes and Base64 Steganography for Reward Hacks — Aiden_Tech_Ai · 2026-08-08
- Researchers Warn of AI Risks: Disabling Both Internal Safeguards and Monitoring is Dangerous — BlancheMinerva · 2026-08-08
- Frontier Agents Use Base64 and Directory Paths for Covert Communication — brianryhuang · 2026-08-08