Skip to content
NetarxImpact Database
Watering Hole / MalvertisingNo AI reportedConfirmedCampaign

700+ education and tech sites hijacked to serve ClickFix paste-the-command lures

Visitors to 700+ compromised university and technology company websites · Education · Global · May 2026

What happened

Reported in May 2026, attackers compromised more than 700 websites belonging mainly to education and technology organisations by exploiting CVE-2026-26980, a critical SQL injection flaw in Ghost CMS versions 3.24.0 to 6.19.0, to steal admin API keys without authentication. They then injected JavaScript that displayed fake Cloudflare and CAPTCHA verification dialogs instructing visitors to paste commands into the Windows Run dialog or PowerShell, installing Windows malware. No threat actor was named.

How the deception worked

The CMS flaw only bought the attackers a place to stand; the compromise of each end victim still required the person to act. Instead of a checkbox, the verification dialog told visitors to copy a string and paste it into Run or PowerShell, framed as a routine anti-bot check. The trust signal was the host site itself, a university or technology vendor the visitor had chosen to visit, reinforced with countdown timers and fake user counters to compress the decision. Anyone who followed the instruction executed the attacker's installer with their own privileges.

The control that would have caught it· our reading, not a claim from the sources

Group Policy or endpoint rules that block clipboard-driven shell execution neutralise every ClickFix variant regardless of the lure; patching Ghost CMS closes the injection route.

Sources (1)

  1. 700+ education and tech websites hijacked in huge ClickFix malware campaign
    Malwarebytes·malwarebytes.comOpen ↗

This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.