A new ClickFix campaign is hiding behind fake Cloudflare pages on hacked Ukrainian sites. Here's how it tricks you into installing the Psychedelic stealer — and how to stay safe.
Imagine clicking a Cloudflare verification box on a normal business site, only to end up with a password-stealing program on your computer. That's exactly what's happening right now in an active ClickFix campaign targeting legitimate Ukrainian business websites.
Security researchers have spotted a wave of compromised sites injecting fake Cloudflare "verify you're human" pages. Once you interact with the page, it silently copies a Windows Installer command to your clipboard and tells you to paste it into the Run dialog. Do that, and you're installing Psychedelic, a previously undocumented information stealer.
### Why This ClickFix Trick Works So Well
The genius of ClickFix is that it turns you into the attacker. Instead of exploiting a software bug, it exploits your trust in a familiar brand like Cloudflare. You see the logo, you assume it's safe, and you follow the instructions without a second thought.
- The lure copies a malicious command to your clipboard automatically.
- A popup tells you to press Windows + R, paste, and hit Enter.
- The command downloads and runs the Psychedelic stealer in the background.
- No obvious warning signs appear until it's too late.
### What Psychedelic Stealer Actually Takes
Once inside, Psychedelic goes after the stuff that matters most. According to early analysis, it targets:
- Saved passwords in browsers like Chrome, Edge, and Firefox
- Cookies and session tokens that let attackers hijack logged-in accounts
- Cryptocurrency wallet files and browser extension data
- System information to help attackers tailor follow-up attacks
> "The most dangerous part isn't the malware itself — it's how ordinary the whole process feels. You're just pasting a command, right?"
That's the trap. It feels routine. And that's why so many people fall for it.
### Who's Behind It and Who's at Risk
The campaign appears to focus on Ukrainian business sites, but the technique isn't limited by geography. Any site running outdated CMS software, weak admin credentials, or unpatched plugins can become a host for these fake verification pages. If you run a website — especially a small business site — you're a potential unwitting accomplice.
For regular users, the risk is just as real. You don't need to visit a shady site. You just need to land on a compromised legitimate one and follow the instructions.
### How to Protect Yourself Right Now
You don't need a security team to stay safe. A few simple habits go a long way:
- Never paste commands from a website into the Run dialog or terminal.
- If a site asks you to "verify" by running something, close the tab.
- Keep your browser and operating system updated.
- Use a reputable password manager and enable two-factor authentication.
- If you run a website, update your CMS, plugins, and admin passwords today.
### The Bigger Picture for Antidetect Browser Users
If you're using antidetect browsers for managing multiple accounts, this campaign is a reminder that your browser environment is only as safe as the sites you visit. A compromised site can still trick you into running malware, no matter how clean your fingerprint looks. Stay skeptical, verify everything, and never run commands you didn't write yourself.
This isn't about being paranoid. It's about being aware. The bad guys are counting on you to click without thinking. Don't give them that satisfaction.