Global ClickFix Campaign on WordPress Sites Actively Blocks AI Crawlers

cyb3rops · x · 2026-08-08

Security researchers uncovered a ClickFix campaign targeting compromised WordPress sites globally. Attackers injected polymorphic JavaScript that filters bot-like User-Agents, specifically including headless browsers, ChatGPT, and Anthropic, to evade detection.

The loader removes its own <script> tag, XOR-obfuscates telemetry, and POSTs data to a C2 server. The server returns XOR-decoded responses executed via indirect eval(), allowing arbitrary JavaScript execution in the victim's browser. 44 affected sites across 15 countries have been identified so far.

Original post →

More from Safety

Safety channel →