# ClickFix to a macOS Stealer, Served From Thousands of Hacked WordPress Sites

An analytics-looking script injected into compromised WordPress sites shows Mac visitors a fake verification step, then has them paste a command that installs a wallet-and-browser stealer. The lure domains rotate daily on sanctioned hosting; the injection persists through core updates.

Provenance: Observed in Report URI crawler data and threat intelligence.
Published: 2026-09-22. Updated: 2026-09-22.

This is the same social-engineering idea as any other ClickFix chain - the page asks the visitor to
run the payload themselves, so nothing malicious is downloaded for a browser control to catch - but
it is worth tracking in its own right because of where it lives and who it targets.

## The injection hides as an analytics tag

The compromised sites are ordinary WordPress installs - small businesses, clinics, schools, a run of
government and diplomatic sites - with one script added to every page. It is labelled to sit
unnoticed next to real Google tags:

```
<script id="ganalytics-tracker-js" src="[rotating-domain]/t.js?site=[hex32]">
```

The `site` value is a stable per-victim identifier, so the same site keeps the same token while the
domain it loads from changes underneath it.

## Patching the site does not clean it

The loader is emitted through WordPress's own script API rather than hardcoded into a template, which
means it is enqueued by code the attacker left behind - a must-use plugin, a modified theme
`functions.php`, or a stored option. Core updates do not touch any of those. A site can be running
the current WordPress release and still serve the loader on every page, which is exactly what we see:
many affected sites are fully patched. Cleaning one means removing the injected enqueue and finding
the persistence behind it, not updating core.

## The domains rotate; the hosting does not

The lure domains burn fast - a fresh one appears roughly daily - and run three naming styles in
parallel: random adjective-noun-gibberish, Google-Analytics typosquats, and analytics-flavoured
words on cheap top-level domains. Chasing them one at a time is a losing game. What holds still is
the hosting: every lure origin we resolved sits on the same sanctioned network, so the autonomous
system is a far better pivot than any single domain.

## What the visitor is shown

On a Mac, the loader renders a fake reCAPTCHA, then a "verification steps" panel that walks the
person through opening Terminal and pasting a command. The command is a decoy line followed by a
base64 blob piped to a shell, which pulls a macOS stealer that goes after crypto wallets, browser
logins and the Keychain. Everything harmful happens in a terminal the browser cannot see, so the
page-side evidence is the overlay and the connection that delivered it.

## What to look for

The loader has to come from somewhere, so an unfamiliar host in `script-src` reports on a page that
has no reason to load third-party analytics is the first signal - especially a freshly registered
domain on an unusual top-level domain. Because the domains rotate, alert on the shape rather than the
name, and treat a script host that appears once and is never seen again as worth a look rather than
something to tune away.

## Indicators

- 45.131.215.56
- 45.147.31.197
- 45.150.33.128
- 95.163.153.80
- analyticshore.icu
- apparatinpi22.life
- ashen-trace-zephyr-draeix.life
- bloodhorn8123.icu
- brisk-forge-willow-caium.life
- buysypi831.life
- cabskaiyn-crane.life
- carwowk872.life
- cirkoborpi.life
- clickstream.icu
- closegate21.xyz
- coral-weave-wren-veis.com
- coral-zephyr-koarseara.xyz
- costum342183.life
- cuiskceogflayn.pro
- datapointly.icu
- dollllar881122.icu
- elizium999.digital
- evrything-pix.icu
- faircloud512421.buzz
- fern-crane-ziankroaum.life
- fern-trace-anvil-meoix.live
- gaezskoynbrisk.com
- gearlipi72.life
- girlsonpi823.life
- gixxipi9823.life
- glacial-bloom-wren-croaon.life
- glacial-sketch-otter-triis.life
- glustrioenbrisk.life
- gonfuirkgroao.life
- googlanalitlcs.icu
- googlanalitlcs.live
- googlanalitlcs.pro
- googlanalitlcs.xyz
- grove-kaee-j4jgh.lol
- hollow-badger-moasfraum.life
- hollow-forge-rook-guiyn.life
- insightpixel.icu
- kiln-skioi-c29up.com
- krestmoais-reed.life
- lofsloatkioa.pro
- logicvault.icu
- longslimpi.life
- mesa-braior-k3w3b.life
- metricspixel.live
- metricvault.icu
- metrix-getrix.icu
- moss-froggaee.space
- nick-metry.icu
- norrykilu231.digital
- pageglance.icu
- pagestatix.icu
- pathaudit.info
- pixelinsights.xyz
- pixelmetrics.live
- preokcriix.live
- quiet-ridge-slaikdoaen.com
- reed-pavcaeor.life
- relmciarnlioix.life
- rerrioara.live
- ridge-ciosktai.site
- rokkyho32.life
- sable-orbit-wren-fiayn.live
- shaltaypi.life
- siteinsights.icu
- skaedbraearaquiet.life
- stoppingignpi.buzz
- strongerpi921.life
- thunderstopui912.life
- trackmetrica.icu
- trilliot6776.icu
- trokuni412.icu
- trombler312.life
- usual-pixx12.digital
- vailora231.life
- vale-quaiyn-jtbn8.life
- velvet-otter-glagceis.life
- visitorflow.icu
- vivid-roam-cove-gleon.life
- voyag413.xyz
- webpulsedata.icu
- webtracelab.icu
- workworm1412.buzz

## Questions

### How does this campaign reach people?

Through legitimate but compromised WordPress sites. A script is injected into the pages, disguised as an analytics tag, and it shows a fake reCAPTCHA to visitors on macOS. The site owner is a victim, not the operator.

### Why does patching WordPress not fix an affected site?

The malicious loader is added through WordPress's own script API from code left behind after the compromise - a must-use plugin, a modified theme file, or a database option. A core update replaces core files and leaves that untouched, so a fully patched site can keep serving the loader.

### Would a CSP catch this?

Yes. The injected loader has to come from somewhere, so an unfamiliar host in script-src reports on a page that has no reason to load third-party analytics is the signal. The lure domains rotate, so the useful thing to alert on is the shape - a freshly registered domain you never authorised appearing in script-src.

### Why only macOS?

This arm of the campaign checks the visitor is on a Mac desktop before it shows anything, and the pasted command and payload are macOS-specific. The same operators run Windows arms elsewhere; the tracked hosts here are the ones seen serving the macOS chain.
