Security1 distinct publisher3 min readUpdated
Sophos says a June 2026 campaign used winget to install the Deno runtime on victim machines, then used deno.exe to fetch, run and persist remote JavaScript ending in a Python infostealer.
The Watch · Security desk
Compiled by The WatchSomething wrong?How this is made
Sophos Counter Threat Unit researchers investigated a June 2026 intrusion set in which the Deno JavaScript runtime served as the core execution mechanism inside a ClickFix chain, with the legitimate deno.exe fetching and running remote JavaScript from attacker infrastructure [1][8]. The consequence is that the interesting half of the intrusion no longer happens in PowerShell or in a custom loader, but inside a code-signed developer binary that Deno's own maintainers shipped in signed form specifically so that security controls would stop flagging it [9][14].
The delivery end is unremarkable. On June 3 and June 4, compromised WordPress sites served Cloudflare-themed ClickFix lures [2]. The lures came from malicious JavaScript injected into site main pages, referencing a script at columbnezhjdq[.]com named goolgetagmanager.js, which ran browser environment checks before presenting staged verification prompts [3]. The injected script was consistent across incidents, but the _cb query parameter varied by site [4]. Victims were told to paste a PowerShell command into Windows Terminal [5].
What that command starts is the part worth reading twice. It triggered an MSI-based staging chain that wrote command-line and PowerShell components into the user's AppData directory [6]. The MSI executed two embedded scripts, november85.cmd and Griffin20.ps1 [7]. Those used winget.exe, the native Windows package manager, to download and install the Deno runtime, after which deno.exe pulled a remote JavaScript payload from webstizkgao[.]com [8]. According to CTU, this let the operators run code remotely without a traditional malware loader [9].
Deno then acted as orchestrator: further PowerShell scripts, system reconnaissance, and persistence through registry Run keys that invoke JavaScript via a headless conhost.exe process [10]. The remote JavaScript delivered a Python payload, install.pyc, executed through pythonw.exe and retrieved from 162[.]33[.]177[.]16 [11]. Sophos analysts confirmed that payload as an infostealer collecting system information, browser and extension data, cryptocurrency wallet data, and keystrokes, alongside telemetry showing system profiling and anti-analysis behaviour [12][13].
Command and control continued through a scheduled task running deno.exe against a remote script at webstizkgao[.]com [15]. On June 23 that script changed to point at a TryCloudflare-hosted staging URL, with downloaded content written into a new registry key disguised as a Microsoft Edge update [16].
Scale came from the web, not from targeting. CTU identified more than 500 compromised WordPress sites carrying similar injections talking to the same two domains, and assessed that the operators used bulk compromise or injection rather than picking targets [17][19]. Columbnezhjdq[.]com was registered on June 1, 2026, five days after webstizkgao[.]com, which puts the earlier registration around May 27, 2026 [18][20].
Deno's signed distributions arrived in the v2.3 release of May 2025, roughly thirteen months before this campaign, and researchers warned then that it could be abused to execute malicious payloads [14][21][22]. Its ability to retrieve remote code, run from user-writable directories, and execute with broad permissions is what makes it fit for multi-stage delivery [23].
Things to watch: winget installing Deno on hosts with no developer justification; scheduled tasks or Run keys whose command line is deno.exe pointing at an HTTP URL [10][15]; and registry values named to look like Edge update state [16]. Allowlisting that trusts signatures and detection that watches only powershell.exe will see none of it.
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
Sophos Counter Threat Unit (CTU) researchers investigated a June 2026 campaign in which threat actors used the Deno JavaScript runtime as a core execution mechanism within a ClickFix-driven intrusion chain, supporting payload delivery, follow-on tasking, and persistence.
On June 3 and June 4, compromised WordPress sites served Cloudflare-themed ClickFix lures that prompted users to execute a clipboard-delivered PowerShell command.
The ClickFix attack relied on malicious JavaScript injected into the main pages of compromised WordPress sites; CTU identified injected script references to hxxps://columbnezhjdq[.]com/goolgetagmanager.js, which performed browser environment checks before presenting staged verification prompts and ClickFix instructions.
The injected script was consistent across the investigated incidents, but the _cb value in the URL query string varied across compromised WordPress sites.
In observed cases, the lure presented the user with a PowerShell command to execute via Windows Terminal.
The executed PowerShell command triggered an MSI-based staging chain that invoked command-line and PowerShell components written to the user's AppData directory.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Detailed first-party telemetry, single vendor
The report is grounded in investigated incidents with a named process tree, two embedded script filenames, specific staging and C2 URLs, a payload IP, a payload filename and published detection rule names - unusually concrete for a threat write-up. It is nonetheless one publisher's own telemetry with no independent corroboration, no victim scope and no third-party sample analysis in the cluster.
Live campaign with mass delivery footprint
Adoption here is real-world use of the technique by attackers: confirmed intrusions on specific dates, a maintained C2 that was re-tooled on June 23, and an injection footprint of more than 500 compromised WordPress sites. Scale of actual victim compromise is undisclosed, so this is credible mass delivery with unquantified success.
Roughly aligned, mildly vendor-flavoured
The framing tracks the evidence closely: the claim is that a signed runtime was used as a loader, and the chain is documented step by step with IOCs. Slightly positive because the technique is a variation on established living-off-trusted-tools tradecraft rather than a new class of threat, because the 500-site figure measures lure exposure rather than compromise, and because the publisher's own detection rules are listed alongside the analysis.
Security vendor publishing its own protections
The only source is a commercial security vendor's research blog that closes with eight of its own detection rule identifiers and hardening recommendations. That is a legitimate and standard disclosure format, but the publisher benefits commercially from demonstrating visibility into the campaign, and no non-vendor party in the cluster checks the findings.
Specific and internally consistent, unreplicated
High confidence in the mechanics of the chain given named artifacts, dates and indicators that are consistent across the report; lower overall because the cluster contains a single publisher, offers no attribution or victimology, and includes no response from Deno or Microsoft on the winget-driven install path.
security
Bring Your Own Runtime: Sophos MDR maps a repeatable Deno-based intrusion chain1 distinct publisher
security
A year of Sophos AI cases: 30 of 38 were fake installers, not autonomous attackers1 distinct publisher
security
ClickFix in the sidebar: Def Con follow-up phishing turns a real Google Doc into the payload2 distinct publishers
leadership
The extortion call now comes from your help desk, and the fix is a procedure you own1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 10, 2026