Known malicious kitcriticalphishing
ClearFake / ClickFix 'enterprise2026' cluster — bscSl fake WordPress plugin loader (YARA)
family: clearfake-enterprise26-2026-08
Content match for the first stage on compromised WordPress sites: the fake plugin script bsc-loader.js (guard window.__bscSlRan) or the settings object WordPress prints for it, var bscSl = {ajaxUrl, nonce, action: "bsc_sl_get_script"}. The loader POSTs to the site's admin-ajax endpoint and injects the returned EtherHiding contract reader.
Anchors
YARA ruleClearFake_BscSl_WordPress_Plugin_Loader
Provenance
Added: 2026-09-25 12:24
Survives the per-site plugin rename (seen as modula-gallery-68 and exactmetrics-pro-2) because it keys on content, not path. The bsc_sl_get_script action name alone is sufficient; the other strings require at least two properties of the settings object together. Complements the exact-hash row, which only catches byte-identical copies.
Sightings (3)
| Host | Scan | Script | Match | When |
|---|---|---|---|---|
| rcrsinnovations.com#html | b898f2e3… | https://rcrsinnovations.com#html | yara | 2026-09-25 12:24 |
| osmilano.it#html | 99e574cc… | https://osmilano.it#html | yara | 2026-09-25 12:24 |
| rcrsinnovations.com | e7aa41f1… | http://rcrsinnovations.com/wp-content/plugins/exactmetrics-pro-2/js/bsc-loader.js#html | yara | 2026-09-25 12:24 |