Known malicious kitcriticalphishing
ClearFake / ClickFix 'enterprise2026' cluster — fake WordPress plugin loader bsc-loader.js (exact content)
family: clearfake-enterprise26-2026-08
The first stage on compromised WordPress sites is a fake plugin script, wp-content/plugins/<plausible-plugin-name>/js/bsc-loader.js (seen as modula-gallery-68 and exactmetrics-pro-2). It POSTs to the site's own admin-ajax endpoint with a localized bscSl {action, nonce, ajaxUrl} object and injects whatever script comes back, which then reads the EtherHiding contract. Guarded by window.__bscSlRan.
Anchors
SMQL queryrun
js_sha256:2dd3cb0cd831f4967f58e4915959fe5fd248a2428fbf529d0b673b27ebcbd0bfProvenance
Added: 2026-09-25 12:01
Byte-exact hash of the loader as served on the first observed site: a tripwire for byte-identical reuse. The plugin directory name is randomised per site, so the durable anchor is content (window.__bscSlRan, bscSl.ajaxUrl) rather than path; a YARA rule on those identifiers would outlive a one-byte edit. The obfuscated second-stage scripts (/js/my, mpackage.js) were not anchored by hash because they appear to be regenerated per request.