Date: 09/15/2026
Severity: High
Summary
A compromised regional news outlet injected malicious JavaScript that triggers a ClickFix prompt, using a cookie check to control execution. The lure tricks users into running an obfuscated CMD/PowerShell command, which downloads and executes an encrypted, compressed payload. The payload is reflectively loaded in memory and ultimately delivers Stealc InfoStealer, enabling credential/session-token theft through browser-focused process injection.
Indicators of Compromise (IOC) List
Domain/URLs | chunks.cdnsuicaches.com Mnl.ac |
IP Address | 45.74.7.27 23.227.198.199 |
Hash | 1e4246ed2050b7a6c711aae4732e8ec89d590dec860d16ecc86071339792135f
41da18c32a2c759946acd9e2291e937b0777e19db6407126807f9af52374e3c0
|
Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection
Detection Query 1 : | domainname like "Mnl.ac" or url like "Mnl.ac" or siteurl like "Mnl.ac" or domainname like "chunks.cdnsuicaches.com" or url like "chunks.cdnsuicaches.com" or siteurl like "chunks.cdnsuicaches.com" |
Detection Query 2 : | dstipaddress IN ("45.74.7.27","23.227.198.199") or srcipaddress IN ("45.74.7.27","23.227.198.199") |
Detection Query 3 : | sha256hash IN ("41da18c32a2c759946acd9e2291e937b0777e19db6407126807f9af52374e3c0","1e4246ed2050b7a6c711aae4732e8ec89d590dec860d16ecc86071339792135f")
|
Reference:
https://github.com/PaloAltoNetworks/Unit42-timely-threat-intel/blob/main/2026-09-14-Regional-News-Outlet-Infected-With-Malicious-JavaScript.txt