ClickFix Campaign Abuses Deno Runtime for Infostealer Delivery

    Date: 08/13/2026

    Severity: High

    Summary

    ClickFix campaign that used compromised WordPress websites and Cloudflare-themed social engineering lures to trick users into executing a malicious PowerShell command. The attack abused the legitimate Deno JavaScript runtime and winget to install Deno, execute remote JavaScript, and deliver a Python-based infostealer through an MSI staging chain. The malware also established persistence via Registry Run keys, performed system reconnaissance, and demonstrated fileless execution techniques to evade traditional endpoint detection. 

    Indicators of Compromise (IOC) List

    Domain/URLs

    columbnezhjdq.com

    webstizkgao.com

    ordinary-computer-analytical-spell.trycloudflare.com

    IP Address

    162.33.177.16

    Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection

    Detection Query 1 :

    domainname like "columbnezhjdq.com" or url like "columbnezhjdq.com" or siteurl like "columbnezhjdq.com" or domainname like "ordinary-computer-analytical-spell.trycloudflare.com" or url like "ordinary-computer-analytical-spell.trycloudflare.com" or siteurl like "ordinary-computer-analytical-spell.trycloudflare.com" or domainname like "webstizkgao.com" or url like "webstizkgao.com" or siteurl like "webstizkgao.com"

    Detection Query 2 :

    dstipaddress IN ("162.33.177.16") or srcipaddress IN ("162.33.177.16")

    Reference: 

    https://www.sophos.com/en-us/blog/clickfix-campaign-abuses-deno-runtime-for-infostealer-delivery         


    Tags

    MalwareClickFixWordPressSocial EngineeringDenoPythonInfostealerPowerShell Attack

    « Previous ArticleNext Article »

    Comments

    No records to display

    Looking for Something?
    Threat Research Categories:
    Tags