ChatGPT user dropped into malicious Custom GPT mid-task in ClickFix malware attack

BarracudaLittle4376 · reddit · 2026-10-06

A ChatGPT Plus subscriber warns that on the official site, between stopping an image generation and requesting a PDF, he was silently dropped into a malicious Custom GPT (URL with a g-xxxx ID, display name "GPT-5.6 Sol") without ever browsing the GPT Store.

The fake page uses the classic ClickFix pattern: it asks the user to press Win+R, type cmd, hit Ctrl+V and press Enter. JavaScript silently copies a malicious command to the clipboard, tricking the user into executing it themselves. The author calls it a nastier pattern than typical phishing and advises heavy ChatGPT users to stay alert.

Original post →

More from Safety

Safety channel →