Threat Intelligence

ClickFix to a macOS Stealer, Served From Thousands of Hacked WordPress Sites

An analytics-looking script injected into compromised WordPress sites shows Mac visitors a fake verification step, then has them paste a command that installs a wallet-and-browser stealer. The lure domains rotate daily on sanctioned hosting; the injection persists through core updates.

Published 22 September 2026

This is the same social-engineering idea as any other ClickFix chain - the page asks the visitor to run the payload themselves, so nothing malicious is downloaded for a browser control to catch - but it is worth tracking in its own right because of where it lives and who it targets.

The injection hides as an analytics tag

The compromised sites are ordinary WordPress installs - small businesses, clinics, schools, a run of government and diplomatic sites - with one script added to every page. It is labelled to sit unnoticed next to real Google tags:

<script id="ganalytics-tracker-js" src="[rotating-domain]/t.js?site=[hex32]">

The site value is a stable per-victim identifier, so the same site keeps the same token while the domain it loads from changes underneath it.

Patching the site does not clean it

The loader is emitted through WordPress's own script API rather than hardcoded into a template, which means it is enqueued by code the attacker left behind - a must-use plugin, a modified theme functions.php, or a stored option. Core updates do not touch any of those. A site can be running the current WordPress release and still serve the loader on every page, which is exactly what we see: many affected sites are fully patched. Cleaning one means removing the injected enqueue and finding the persistence behind it, not updating core.

The domains rotate; the hosting does not

The lure domains burn fast - a fresh one appears roughly daily - and run three naming styles in parallel: random adjective-noun-gibberish, Google-Analytics typosquats, and analytics-flavoured words on cheap top-level domains. Chasing them one at a time is a losing game. What holds still is the hosting: every lure origin we resolved sits on the same sanctioned network, so the autonomous system is a far better pivot than any single domain.

What the visitor is shown

On a Mac, the loader renders a fake reCAPTCHA, then a "verification steps" panel that walks the person through opening Terminal and pasting a command. The command is a decoy line followed by a base64 blob piped to a shell, which pulls a macOS stealer that goes after crypto wallets, browser logins and the Keychain. Everything harmful happens in a terminal the browser cannot see, so the page-side evidence is the overlay and the connection that delivered it.

What to look for

The loader has to come from somewhere, so an unfamiliar host in script-src reports on a page that has no reason to load third-party analytics is the first signal - especially a freshly registered domain on an unusual top-level domain. Because the domains rotate, alert on the shape rather than the name, and treat a script host that appears once and is never seen again as worth a look rather than something to tune away.

Indicators

The hosts we're tracking for this campaign

These are the entries in our threat intelligence feed for this campaign, shown exactly as we match them. An entry starting *. covers that domain and everything under it, so an attacker cycling through subdomains doesn't get away from it. We only do that when the attacker registered the domain themselves.

The feed changes as we go. We add hosts when they show up and pull them out when the evidence no longer holds, so this is what we're matching today rather than a permanent record.

45.131.215.56
45.147.31.197
45.150.33.128
95.163.153.80
analyticshore.icu
apparatinpi22.life
ashen-trace-zephyr-draeix.life
bloodhorn8123.icu
brisk-forge-willow-caium.life
buysypi831.life
cabskaiyn-crane.life
carwowk872.life
cirkoborpi.life
clickstream.icu
closegate21.xyz
coral-weave-wren-veis.com
coral-zephyr-koarseara.xyz
costum342183.life
cuiskceogflayn.pro
datapointly.icu
dollllar881122.icu
elizium999.digital
evrything-pix.icu
faircloud512421.buzz
fern-crane-ziankroaum.life
fern-trace-anvil-meoix.live
gaezskoynbrisk.com
gearlipi72.life
girlsonpi823.life
gixxipi9823.life
glacial-bloom-wren-croaon.life
glacial-sketch-otter-triis.life
glustrioenbrisk.life
gonfuirkgroao.life
googlanalitlcs.icu
googlanalitlcs.live
googlanalitlcs.pro
googlanalitlcs.xyz
grove-kaee-j4jgh.lol
hollow-badger-moasfraum.life
hollow-forge-rook-guiyn.life
insightpixel.icu
kiln-skioi-c29up.com
krestmoais-reed.life
lofsloatkioa.pro
logicvault.icu
longslimpi.life
mesa-braior-k3w3b.life
metricspixel.live
metricvault.icu
metrix-getrix.icu
moss-froggaee.space
nick-metry.icu
norrykilu231.digital
pageglance.icu
pagestatix.icu
pathaudit.info
pixelinsights.xyz
pixelmetrics.live
preokcriix.live
quiet-ridge-slaikdoaen.com
reed-pavcaeor.life
relmciarnlioix.life
rerrioara.live
ridge-ciosktai.site
rokkyho32.life
sable-orbit-wren-fiayn.live
shaltaypi.life
siteinsights.icu
skaedbraearaquiet.life
stoppingignpi.buzz
strongerpi921.life
thunderstopui912.life
trackmetrica.icu
trilliot6776.icu
trokuni412.icu
trombler312.life
usual-pixx12.digital
vailora231.life
vale-quaiyn-jtbn8.life
velvet-otter-glagceis.life
visitorflow.icu
vivid-roam-cove-gleon.life
voyag413.xyz
webpulsedata.icu
webtracelab.icu
workworm1412.buzz

Observed in Report URI crawler data and threat intelligence. We classify these on what we saw them doing, not on any claim about who runs them.

Disputing a classification →

FAQ

Frequently asked questions

Through legitimate but compromised WordPress sites. A script is injected into the pages, disguised as an analytics tag, and it shows a fake reCAPTCHA to visitors on macOS. The site owner is a victim, not the operator.

The malicious loader is added through WordPress's own script API from code left behind after the compromise - a must-use plugin, a modified theme file, or a database option. A core update replaces core files and leaves that untouched, so a fully patched site can keep serving the loader.

Yes. The injected loader has to come from somewhere, so an unfamiliar host in script-src reports on a page that has no reason to load third-party analytics is the signal. The lure domains rotate, so the useful thing to alert on is the shape - a freshly registered domain you never authorised appearing in script-src.

This arm of the campaign checks the visitor is on a Mac desktop before it shows anything, and the pasted command and payload are macOS-specific. The same operators run Windows arms elsewhere; the tracked hosts here are the ones seen serving the macOS chain.

Find out if this is running on your site.

We flag these hosts in your own reports automatically, so you hear about it from us instead of from your customers.

← All threat intelligence research · Read this page as Markdown