Threats & Adversaries · Credential Theft

Over 250 WordPress Sites Serve ClickFix CAPTCHA Infostealers

The ClickFix prompt tricks users into pasting a Windows Run command that launches in-memory infostealers. Observed payloads (Vidar, Impure, Vodka, Double Donut) steal credentials and crypto wallets.

3 sources · Mar 16

Timeline

Sources

Part of the PlainSec briefing for 2026-03-12

Every edition of this story: Over 250 WordPress Sites Serve ClickFix CAPTCHA Infostealers

More from today