Rapid7 tracked a campaign that compromised 250+ legitimate WordPress sites to inject a fake Cloudflare 'ClickFix' CAPTCHA that delivers a multi-stage Windows stealer. The malware runs mainly in memory and steals credentials and crypto wallets, enabling financial theft and follow-on intrusions
Part of the PlainSec briefing for 2026-03-19