Bleepingcomputer
ClickFix JavaScript Attack Targets Cryptocurrency Users via Pastebin
First seen 15 Feb 2026, 19:07 UTC
•
•22.3
Export
Article Content
Browse articles
Threat actors are exploiting Pastebin to launch a ClickFix-style attack that deceives cryptocurrency users into executing malicious JavaScript in their browsers. This attack hijacks Bitcoin swap transactions, redirecting funds to wallets controlled by the attackers, and relies on social engineering tactics promising high returns from a fake Swapzone.io arbitrage exploit.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Timeline
2026-02-15
Attack reported using Pastebin for ClickFix-style JavaScript attack
More articles in this cluster
Continue Reading
Ghost CMS SQL Injection Exploits 700+ Sites in Ongoing ClickFix Campaign
Russian GRU Hackers Use Fake CAPTCHAs to Compromise Ukrainian Users
Kimsuky Exploits South Korean Groupware Vendors with New Gomir Variants
Rapid7 Reports Surge in Vulnerability Exploitation Outpacing Patching Efforts
ACSC Issues Critical Alert on Exploited CMS Vulnerabilities
Cybercriminals Exploit BNB Chain for Malware via Fake CAPTCHAs