Paste-to-Run Attacks Break Endpoint Assumptions

ClickFix works because the user becomes the execution step. That means a normal-looking paste into a trusted prompt can look legitimate to AV and EDR, even though it is the handoff that runs the malware. ReliaQuest says this tactic dominated malware delivery from March 1 to May 31, 2026, and it spread from Windows into macOS. The macOS change matters because attackers moved from Terminal to Script Editor after Apple added paste-time warnings in Terminal, and the payloads included Deepload and AMOS. For defenders, the shift is not just a new lure. It shows the technique can move across platforms and around vendor warnings as long as users can paste commands into a trusted workflow.

Part of the PlainSec briefing for 2026-07-02

Sources