Known malicious kitcriticalphishing

ClearFake / ClickFix 'enterprise2026' cluster — bscSl fake WordPress plugin loader (YARA)

family: clearfake-enterprise26-2026-08

Content match for the first stage on compromised WordPress sites: the fake plugin script bsc-loader.js (guard window.__bscSlRan) or the settings object WordPress prints for it, var bscSl = {ajaxUrl, nonce, action: "bsc_sl_get_script"}. The loader POSTs to the site's admin-ajax endpoint and injects the returned EtherHiding contract reader.

Anchors

YARA ruleClearFake_BscSl_WordPress_Plugin_Loader

Provenance

Added: 2026-09-25 12:24
Survives the per-site plugin rename (seen as modula-gallery-68 and exactmetrics-pro-2) because it keys on content, not path. The bsc_sl_get_script action name alone is sufficient; the other strings require at least two properties of the settings object together. Complements the exact-hash row, which only catches byte-identical copies.

Sightings (3)

HostScanScriptMatchWhen
rcrsinnovations.com#htmlb898f2e3…https://rcrsinnovations.com#htmlyara2026-09-25 12:24
osmilano.it#html99e574cc…https://osmilano.it#htmlyara2026-09-25 12:24
rcrsinnovations.come7aa41f1…http://rcrsinnovations.com/wp-content/plugins/exactmetrics-pro-2/js/bsc-loader.js#htmlyara2026-09-25 12:24