Ukraine's CERT-UA identified more than 100 compromised websites injecting JavaScript that serves LunexStealer, also called Psychedelic Stealer. The cluster is tracked as UAC-0277. Visitors get a forged Cloudflare verification page and are told to prove they are human by running a command. That command downloads a malicious MSI. This is the ClickFix pattern, now paired with a stealer that also takes the browser.
What happened
The injected script does not hard-code its lure. It pulls the loader domain and an operating mode from a smart contract on Polygon or Ethereum, a technique known as EtherHiding. Mode 0 is idle. Mode 1 only tracks visitors. Mode 2 shows the fake check, and only to Windows users who arrived from a search engine, at most twice in 12 hours.
Three MSI variants have been seen. One installs the stealer directly. A second bypasses UAC, adds Microsoft Defender exclusions, and uses a vulnerable signed AMD driver, PDFWKRNL.sys, to blind security tools. A third sideloads a rogue DLL through a legitimate FnHotkeyUtility.exe. The stealer also installs a browser extension posing as Microsoft Office Word Editor, which can steal cookies, history, and form credentials, and can run script in the browser.
Who is affected
Windows users who followed a fake verification prompt on a compromised site, and any organisation whose staff or clients browse from managed endpoints without controls on the Run dialog or MSI installs. CERT-UA did not publish a victim count. The delivery method is aimed at ordinary visitors, not only at administrators.
- Block the Windows Run dialog for standard users
- Stop non-admins from installing MSI packages
- Alert on msiexec.exe launched from a browser or shell one-liner
- Turn on Microsoft's vulnerable-driver blocklist and the ASR rule that blocks abused signed drivers
What to do now
Treat any user who ran a command from a browser verification page as a probable stealer infection, not a phishing miss. Isolate the endpoint, check for unexpected browser extensions, Defender exclusions, and the AMD driver abuse path, then reset browser-stored credentials and session cookies. On your own sites, scan for injected verification scripts that load configuration from a blockchain contract.
Source: The Hacker News, 7 October 2026, 100-plus compromised websites use fake Cloudflare checks to deliver LunexStealer. CERT-UA advisory: article 6319983.
Also on the blog
- CVE-2026-21589: unauthenticated file read on Atlassian Data Center
- FortiBleed: FBI says 86,644 Fortinet device credentials still in play
- CVE-2026-102255: CVSS 10 SSRF in SonicWall SMA1000
- CVE-2026-91140: Progress DataDirect AI agent command injection
Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.