Telemetry and reverse engineering identified msclairty[.]com as a typosquatted domain impersonating Microsoft’s Clarity analytics service (msclarity[.]com / clarity[.]ms) and delivering an obfuscated in-browser ad-fraud payload. The JavaScript was observed being injected by a browser extension (not a compromised site script tag), with consistent behavior across multiple unrelated websites and affected users spanning multiple Chrome versions. Reported behaviors include deleting Google Analytics cookies, affiliate cookie stuffing (e.g., pub=twsc), injecting hidden iframes to discounthero[.]org, and Fetch API hijacking; the reporting also noted that common security tooling did not flag the domain at the time of publication.
Separate reporting described an XWorm malware wave using multi-stage JavaScript and PowerShell loaders that decode and execute payloads in memory, culminating in a DLL exporting ProcessHollowing to inject the XWorm client into the .NET compiler process. That activity included a C2 endpoint 204[.]10[.]160[.]190:7003, an aes_key value XAorWEAzx4+ic89KWd910w==, mutex Cqu1F0NxohroKG5U, and file hashes for the JavaScript, PowerShell loader, DLL, and final payload; however, this malware campaign is unrelated to the msclairty[.]com browser-based ad-fraud activity.
![Typosquatted msclairty[.]com Ad-Fraud JavaScript Injected via Browser Extension](/_next/image?url=https%3A%2F%2Fmallory-core-public-images.s3.us-east-2.amazonaws.com%2Ftyposquatted-msclairtycom-ad-fraud-javascript-injected-via-browser-extension.png&w=3840&q=75)
Trace attribution and downstream blast radius.
5 events from the most recent confirmed update back to the earliest known activity.
The reporting entity said it shared its findings with Microsoft for potential takedown and with RedTrack because the malicious script explicitly targeted RedTrack attribution cookies.
c/side published what it described as the first public documentation of msclairty[.]com, detailing the typosquatted infrastructure, browser-extension injection chain, cookie deletion, hidden iframe redirects to discounthero[.]org, and Fetch API hijacking.
Researchers observed the operation increase on March 3, affecting multiple unrelated industries while remaining limited to a small set of U.S. residential IPs and real Google Chrome on Windows 10.
Telemetry first recorded a coordinated Chrome-on-Windows campaign in which an unknown browser extension injected obfuscated JavaScript from msclairty[.]com. The activity used a staged loader and anti-analysis techniques while conducting affiliate fraud and suppressing competing tracking.
The domain msclairty[.]com, impersonating Microsoft Clarity, received its SSL certificate, suggesting the infrastructure was prepared specifically for the later campaign.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 9 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
2 references tracked. Mallory keeps watching after this page renders.
cside.com
Open sourcecside.dev
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.