Known malicious kitcriticalphishing
ClearFake / ClickFix 'enterprise2026' cluster — fake WordPress plugin path bsc-loader.js (script URL)
family: clearfake-enterprise26-2026-08
Any scan whose page loaded a script at wp-content/plugins/<name>/js/bsc-loader.js, the fake plugin that starts the EtherHiding ClickFix chain on compromised WordPress sites. The plugin directory name is chosen per site to look legitimate (seen as modula-gallery-68 and exactmetrics-pro-2); the file name and its place in the plugin layout stay constant.
Anchors
SMQL queryrun
script_url:*/wp-content/plugins/*/js/bsc-loader.js*Provenance
Added: 2026-09-25 12:36
Path anchor, complementary to the content (YARA) rows: it still fires if the loader's code is rewritten, as long as the file keeps its name. The bare file name is not used on its own; it is required inside a WordPress plugin directory. The second stage's /js/my?<8 chars>&ts=<ms> request shape is deliberately not anchored here because a short generic path like that can occur on unrelated sites.