ClickFix payloads are being distributed through more than 5,400 compromised websites, according to a report published on 5 September 2026. Attackers have injected scripts into legitimate sites and are using blockchain storage as part of the delivery infrastructure.
The campaign creates two groups of potential victims. Website operators face unauthorised changes to their pages and reputational damage, while visitors may encounter deceptive instructions intended to make them run malicious commands on their own devices.
ClickFix payloads found across 5,400 hacked sites
The reported compromise affects more than 5,400 legitimate websites. Rather than building a network of obviously malicious domains, the attackers have modified existing sites so that injected scripts can load ClickFix payloads stored on a blockchain.
This approach allows malicious activity to appear within a website that visitors may already know or trust. The affected sites can also benefit from an established reputation, valid security certificates and existing search visibility, all of which may make the initial page appear less suspicious.
The available report does not identify a particular content management system, hosting provider, website plugin or software version shared by all affected sites. It also does not establish one common initial access method. Organisations should therefore avoid assuming that the incident is restricted to a single web platform or vulnerable product.
Who is affected by the campaign
The immediate victims are the owners and administrators of the compromised websites. An injected script means an attacker has gained some ability to alter the content delivered to visitors, whether through the website itself, a third-party component or another part of its publishing chain.
Visitors to those sites form the second affected group. Exposure does not necessarily mean that a device has been infected, because ClickFix attacks generally depend on social engineering and user interaction. The danger arises when a visitor follows a fake repair, verification or security procedure presented by the malicious page.
No specific browser versions, operating system versions or endpoint products are named in the supplied report. The relevant exposure is therefore behavioural and web-based: a user reaches a compromised page, sees attacker-controlled content and is persuaded to take an unsafe action.
How the ClickFix blockchain attack works
ClickFix is a social engineering technique built around a false technical problem and a supposed quick solution. A page may claim that an error, failed check or access problem can be resolved by copying and running a command. The instruction shifts execution to the victim, helping the attacker bypass some controls that focus on automatic downloads.
In this incident, the attack starts with compromised websites containing injected scripts. Those scripts act as a bridge between the trusted site and the remotely stored ClickFix payloads. The blockchain component gives the attackers an external location from which malicious content or instructions can be retrieved.
A likely interaction follows this broad sequence, although the exact prompts and commands used in every affected site have not been disclosed:
- An internet user visits one of the more than 5,400 compromised websites.
- An unauthorised script runs in the browser or requests additional content.
- The script loads attacker-controlled ClickFix payloads associated with blockchain storage.
- The visitor is shown a deceptive problem, check or instruction.
- If the visitor follows the instruction, a command may execute outside the normal browser download process.
The report does not name the final malware families, command contents or post-compromise activity delivered through the campaign. It is therefore important to distinguish confirmed facts from possible outcomes. The confirmed issue is the large network of hacked sites serving blockchain-hosted ClickFix content.
Why blockchain storage complicates removal
Traditional malicious infrastructure can often be disrupted by suspending a server, removing a file or taking down a domain. Data written to a blockchain may be replicated and difficult to alter directly, giving attackers a more persistent location for their content.
This does not make the campaign impossible to stop. Access can still depend on website injections, blockchain gateways, browser requests and other infrastructure that defenders may block or remove. However, cleaning one compromised website does not erase the underlying blockchain entry, and another infected site may continue to retrieve it.
The model also separates the visible compromise from the payload source. A website owner might remove an obvious malicious page but overlook a small script that continues to fetch remote instructions. Effective remediation therefore requires an integrity review of code, templates, database content and externally loaded resources.
Timeline and current exploitation status
The campaign was publicly reported on 5 September 2026, with more than 5,400 hacked sites identified as serving ClickFix payloads. The source material does not provide a confirmed date for the first website compromise, the earliest blockchain upload or the point at which the operation reached its reported scale.
The scale and active delivery mechanism indicate exploitation in the wild, rather than a theoretical vulnerability or proof of concept. Attackers have already breached legitimate sites and used them to expose visitors to malicious content.
The number should be treated as a reported minimum rather than a fixed total. Additional compromised sites may remain undiscovered, while some identified operators may already be removing injected code. No confirmed end date or complete takedown is described in the available report.
Why this ClickFix campaign matters
The campaign combines trusted websites, user-driven execution and persistent external storage. Each element creates a different challenge: legitimate sites can evade simple reputation checks, ClickFix can persuade users to bypass warnings, and blockchain storage can make the hosted content harder to remove at its source.
For organisations, a visited website does not need to be overtly malicious to create exposure. Security teams may need to investigate browser activity, command execution and unusual outbound requests together, rather than relying only on records of downloaded files.
Actions organisations should take now
Website operators should prioritise checking for unauthorised script changes and unexpected blockchain-related requests. Comparisons against known-good versions can help identify small injections that may be missed during a visual review.
- Review recently modified scripts, templates, plugins and database content.
- Investigate unfamiliar external resources loaded by public web pages.
- Remove injected code, rotate exposed administrative credentials and close the access route.
- Search endpoint logs for commands launched shortly after browser activity.
- Warn staff not to copy and run commands presented by websites as fixes or verification steps.
Network and browser controls should focus on the specific delivery chain, including unexpected script execution and access to unapproved blockchain gateways. Any affected site should be monitored after restoration because removing the visible ClickFix payloads without fixing the original intrusion may allow reinfection.
Originally reported by BleepingComputer.






