wtf sort of verification is this? no fucking way am I going to run whatever is in my buffer that you probably put there. I assume this must be some sort of hijack right?

Edit: yes thank you I know a) not to run it (I didn’t), b) it’s ClickFix, and c) to let the website owners know (I have done this).

I wish Mastodon were better at showing replies so I didn’t have to get the same one a million times

This is a sewing pattern shop website, btw.
@CatherineFlick please tell them they've been hacked.
@CatherineFlick
...that's been hacked. That's a known compromise pattern.
@pikesley I didn't run it, of course. it set off all of the red flags
@CatherineFlick my first thought: that's a prompt injection 😅
@CatherineFlick this is a way of spreading malware that has been rising in popularity (and not an official thing)

@CatherineFlick yes indeed websites can copy stuff to the buffer: e.g. a lot of webapp text editors do it to handle a contextual (right click) "copy" menu inside their elaborate interfaces.

So this hack that pretends to be a clouflare check has surely put some nasty commands in the buffer.

did you paste the buffer into notepad instead, and save it for the posterity?

@CatherineFlick
Never do that, indeed. Basically an 'install your own virus' type situation
@CatherineFlick I saw a video a while ago about this - it's scary how real some of these things look. The first 5 mimutes explains it. https://www.youtube.com/watch?v=ON1z1hUdEdU
Scam Awareness - Fake Authentication and Miracle Cures

YouTube

@UltrasonicMadness Where precisely can I get this miracle eye cure by the way? 💸
(scnr 😇)

@CatherineFlick

@CatherineFlick yes that is hacked website trying to get you to run malware.

@CatherineFlick I still don't understand why browser makers think it's ok for browsers to have direct access to the clipboard. This really really needs to not be a thing...

I was curious what it was going to have people paste, but it looks like they've already fixed it. I opened it up in a TOR browser and it just did the spinning thing and then went straight to the sight without a popup. I'm sort of curious what it tried to run, but it's gone now and good riddance anyway.

ClickFix: How to Infect Your PC in Three Easy Steps – Krebs on Security

@twynn @CatherineFlick
Does it affect only Windows?

@sunflowerinrain @twynn @CatherineFlick

The instructions are specific to Windows. It’s possible that they’ve created a payload that works on other platforms, so if you paste them into some other terminal, who knows what happens.

@CatherineFlick press Enter Enter Enter key
@CatherineFlick Oh wow, that's actually terrifying. The site itself seems legit from a search, but evidently fell victim to a fake CAPTCHA scam. This page describes the exact same thing as an exploit: https://it.lbl.gov/fake-captcha-scams-dont-get-tricked-into-running-malicious-code/
Fake CAPTCHA Scams: Don’t Get Tricked Into Running Malicious Code