Known malicious kitcriticalphishing

ClearFake / ClickFix 'enterprise2026' cluster — fake WordPress plugin loader bsc-loader.js (exact content)

family: clearfake-enterprise26-2026-08

The first stage on compromised WordPress sites is a fake plugin script, wp-content/plugins/<plausible-plugin-name>/js/bsc-loader.js (seen as modula-gallery-68 and exactmetrics-pro-2). It POSTs to the site's own admin-ajax endpoint with a localized bscSl {action, nonce, ajaxUrl} object and injects whatever script comes back, which then reads the EtherHiding contract. Guarded by window.__bscSlRan.

Anchors

SMQL queryrun
js_sha256:2dd3cb0cd831f4967f58e4915959fe5fd248a2428fbf529d0b673b27ebcbd0bf

Provenance

Added: 2026-09-25 12:01
Byte-exact hash of the loader as served on the first observed site: a tripwire for byte-identical reuse. The plugin directory name is randomised per site, so the durable anchor is content (window.__bscSlRan, bscSl.ajaxUrl) rather than path; a YARA rule on those identifiers would outlive a one-byte edit. The obfuscated second-stage scripts (/js/my, mpackage.js) were not anchored by hash because they appear to be regenerated per request.

Sightings (2)

HostScanScriptMatchWhen
rcrsinnovations.comb898f2e3…—query2026-09-25 12:31
osmilano.it99e574cc…—query2026-09-25 12:08