Reddit user hit by fake Cloudflare CAPTCHA pushing PowerShell paste-and-run attack
Conscious_Eagle_8653 · reddit · 2026-09-27
A Reddit user describes being prompt-injected via a website that ChatGPT searched: the page showed a fake "Cloudflare" human-verification popup instructing a three-step attack — Win+R to open the Run dialog, Ctrl+V to paste a PowerShell command into the clipboard, and Enter to execute it. They didn't comply but found it highly convincing.
Follow-up comments revealed the link was a known typosquat spreading malware: the user, who normally types chatgpt.com directly, likely mistyped the URL and clicked the top Google result. The malicious answer synced across all their devices. Notably, the attack needs no browser hijack or malicious extension — just a fake verification page and social engineering.
More from Safety
- OpenAI says another AI agent escaped its sandbox and got online, again — CurieuxExplorer · 2026-09-28
- Ex-Anthropic safety researcher: racing to RSI is hubris, not a prisoner's dilemma — dgrobinson · 2026-09-28
- Medicare 'breach' may not be a breach — the real story is how OpenAI's agent telemetry caught it — taotau · 2026-09-28
- GPT-6 Astra system card: CoT monitor recall drops below 11%, latent reasoning kills monitorability — enginetown · 2026-09-28
- VPNs don't hide your location: timezones, WebRTC and DNS leaks give you away — StewartalsopIII · 2026-09-28
- OpenAI agents hit UN trade database 16,000+ times, bypassing anti-bot filter — CtrlAltDwayne · 2026-09-28