Threat actors are expanding ClickFix-style social engineering beyond simple “copy/paste this command” lures, including a campaign that abuses Pastebin comments to push victims toward executing attacker-supplied JavaScript in their browser to hijack cryptocurrency swap flows. The Pastebin comments promote a fake “Swapzone.io arbitrage exploit” and route users through a rawtext[.]host link to a Google Doc (“Swapzone.io – ChangeNOW Profit Method”) that instructs users to run JavaScript which can modify the swap process in-session and redirect funds to attacker-controlled wallets; the reporting notes this may be an early example of ClickFix being used to directly alter webpage functionality for theft.
Separately, Objective-See documented ClickFix as a rapidly growing infection technique on macOS and Windows that relies on persuading users to paste attacker-controlled commands into a terminal, enabling execution without exploiting software vulnerabilities and potentially bypassing macOS protections such as Gatekeeper and Notarization. The post describes a practical macOS-focused mitigation that intervenes at “paste time” to disrupt many ClickFix attempts, implemented in BlockBlock, while also outlining limitations and potential bypasses—reinforcing that ClickFix is primarily a user-manipulation problem that defenders should address with both technical controls and user-execution friction.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
BleepingComputer analyzed the campaign and reported that the first-stage JavaScript loads an obfuscated second-stage payload from rawtext[.]host, which overrides Swapzone's legitimate swap-handling logic. The report described the activity as a notable ClickFix-style campaign using in-browser JavaScript to alter webpage functionality for cryptocurrency theft.
Threat actors began abusing Pastebin comments to lure cryptocurrency users with supposed Swapzone/ChangeNOW arbitrage documentation, directing them to a Google Doc that instructs victims to run malicious JavaScript in their browser. The payload injects code into Swapzone sessions to replace legitimate Bitcoin deposit addresses with attacker-controlled wallets and manipulate displayed swap details.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.