ClickFix malware has taken a troubling leap forward. Security researchers have identified more than 5,400 compromised websites being used to deliver malicious payloads — and the attackers are storing those payloads directly on the blockchain to make them nearly impossible to take down. If you run a small or medium-sized business, this is not an abstract threat. It is the kind of attack that quietly steals employee passwords, customer data, and business credentials before anyone notices something is wrong.
What Is ClickFix and Why Is It So Effective?
ClickFix is a social engineering technique that tricks users into running malicious commands on their own computers. The typical scenario goes like this: someone on your team visits a legitimate-looking website — perhaps a supplier's page, a news site, or even a business tool — that has been secretly compromised by attackers. A fake error message appears on screen, asking the visitor to click a button or paste a command to "fix" the problem. The moment they do, malware is installed silently in the background.
What makes this wave of attacks especially dangerous is where the malicious code lives. Instead of hosting it on a server that security teams can identify and shut down, attackers are encoding their payloads inside blockchain transactions. The blockchain is permanent and censorship-resistant by design — which means once that code is written there, no one can delete it. Traditional takedown requests, which are already slow, become completely useless.
How Compromised Websites Become a Threat to Your Business
Your employees do not need to visit shady corners of the internet to encounter this threat. The 5,400-plus sites caught serving ClickFix payloads included ordinary, everyday websites that had been quietly hacked without their owners knowing. A compromised WordPress plugin, an unpatched e-commerce platform, an outdated business directory — any of these can become a delivery mechanism for malware targeting your staff.
Once ClickFix successfully executes on a machine, the malware it installs is typically designed to harvest credentials. That means browser-saved passwords, session tokens, VPN logins, and cloud application credentials can all be scooped up and sent to the attacker within minutes. Those stolen credentials then find their way onto dark web markets and infostealer logs, where other criminals buy them to launch further attacks — account takeovers, business email compromise, ransomware.
For a small business, a single compromised employee account can be the entry point for a breach that costs tens of thousands of pounds to recover from.
What the Blockchain Storage Trick Means for Detection
Traditional cybersecurity tools are built to block known malicious URLs and flag suspicious servers. When the payload is stored on a public blockchain, those tools struggle. The request looks like a legitimate network call, and the infrastructure cannot be blacklisted the way a dodgy domain can. This is why attacks like this tend to have longer dwell times — they go undetected for weeks or months while damage accumulates.
It also means that even after the compromised websites are cleaned up, the malicious payload itself remains permanently accessible on the blockchain. Future attackers could reference the same code without needing to host anything themselves. The barrier to launching copycat attacks gets lower over time.
For businesses, the practical implication is that perimeter defences alone are not enough. You need visibility into what is happening after a potential compromise — specifically, whether your credentials or data have already surfaced somewhere they should not be.
How to Protect Your Business From ClickFix Credential Theft
The first step is making sure your team knows not to follow on-screen prompts that ask them to paste commands or click unusual fix buttons, even on websites that look trustworthy. Browser isolation tools and endpoint protection that flags PowerShell or command-line activity from browser processes can also help catch these attacks early.
But given how effective ClickFix malware has become at evading detection, monitoring what happens downstream matters just as much as prevention. If stolen credentials from your business end up in an infostealer dump or appear on a dark web marketplace, you need to know before an attacker uses them. That is exactly what Breachrr monitors — breach databases, infostealer logs, dark web markets, public code repositories, and domain infrastructure — so you get an early warning instead of a nasty surprise.
Run a free audit at breachrr.com/audit to find out whether your business credentials are already exposed.
Want to see if your company is exposed?