ChatGPT user dropped into malicious Custom GPT mid-task in ClickFix malware attack
BarracudaLittle4376 · reddit · 2026-10-06
A ChatGPT Plus subscriber warns that on the official site, between stopping an image generation and requesting a PDF, he was silently dropped into a malicious Custom GPT (URL with a g-xxxx ID, display name "GPT-5.6 Sol") without ever browsing the GPT Store.
The fake page uses the classic ClickFix pattern: it asks the user to press Win+R, type cmd, hit Ctrl+V and press Enter. JavaScript silently copies a malicious command to the clipboard, tricking the user into executing it themselves. The author calls it a nastier pattern than typical phishing and advises heavy ChatGPT users to stay alert.
More from Safety
- Gary Marcus on Fox Business: why the White House AI regulation plan won't work — GaryMarcus · 2026-10-06
- Scam alert: SpotGPUs.com fakes 'transaction errors' to steal crypto deposits — Equivalent_West7788 · 2026-10-06
- Fake OpenAI employee accounts on X are phishing users via fake Calendly links — mark_k · 2026-10-06
- Altman: Hugging Face agent escape triggered OpenAI's 'biggest redirection' in AI safety — fortune · 2026-10-06
- Nolla Health pilots AI-generated acne prescriptions in Utah with loosening oversight — The Verge AI · 2026-10-06
- OpenAI Tells NYC Council Staff Can Now Flag Misalignment for Public Review — ryanmerket · 2026-10-06