Known malicious kitcriticalphishing

ClearFake / ClickFix 'enterprise2026' cluster — fake WordPress plugin path bsc-loader.js (script URL)

family: clearfake-enterprise26-2026-08

Any scan whose page loaded a script at wp-content/plugins/<name>/js/bsc-loader.js, the fake plugin that starts the EtherHiding ClickFix chain on compromised WordPress sites. The plugin directory name is chosen per site to look legitimate (seen as modula-gallery-68 and exactmetrics-pro-2); the file name and its place in the plugin layout stay constant.

Anchors

SMQL queryrun
script_url:*/wp-content/plugins/*/js/bsc-loader.js*

Provenance

Added: 2026-09-25 12:36
Path anchor, complementary to the content (YARA) rows: it still fires if the loader's code is rewritten, as long as the file keeps its name. The bare file name is not used on its own; it is required inside a WordPress plugin directory. The second stage's /js/my?<8 chars>&ts=<ms> request shape is deliberately not anchored here because a short generic path like that can occur on unrelated sites.

Sightings (2)

HostScanScriptMatchWhen
rcrsinnovations.comb898f2e3…—query2026-09-25 12:38
osmilano.it99e574cc…—query2026-09-25 12:38