Security1 publisher3 min readPublished Updated
ClickFix operators install the signed Deno runtime to run their remote JavaScript
Sophos says a June 2026 campaign used winget to install the Deno runtime on victim machines, then used deno.exe to fetch, run and persist remote JavaScript ending in a Python infostealer.
The Watch · Security desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction
What happened
- Sophos Counter Threat Unit (CTU) researchers investigated a June 2026 campaign in which threat actors used the Deno JavaScript runtime as a core execution mechanism within a ClickFix-driven intrusion chain, supporting payload delivery, follow-on tasking, and persistence.
- On June 3 and June 4, compromised WordPress sites served Cloudflare-themed ClickFix lures that prompted users to execute a clipboard-delivered PowerShell command.
- The ClickFix attack relied on malicious JavaScript injected into the main pages of compromised WordPress sites; CTU identified injected script references to hxxps://columbnezhjdq[.]com/goolgetagmanager.js, which performed browser environment checks before presenting staged verification prompts and ClickFix instructions.
- The injected script was consistent across the investigated incidents, but the _cb value in the URL query string varied across compromised WordPress sites.
- In observed cases, the lure presented the user with a PowerShell command to execute via Windows Terminal.
Compiled by The WatchSomething wrong?How this is made
Why it matters
Sophos Counter Threat Unit researchers investigated a June 2026 intrusion set in which the Deno JavaScript runtime served as the core execution mechanism inside a ClickFix chain, with the legitimate deno.exe fetching and running remote JavaScript from attacker infrastructure [1][8]. The consequence is that the interesting half of the intrusion no longer happens in PowerShell or in a custom loader, but inside a code-signed developer binary that Deno's own maintainers shipped in signed form specifically so that security controls would stop flagging it [9][14].
The delivery end is unremarkable. On June 3 and June 4, compromised WordPress sites served Cloudflare-themed ClickFix lures [2]. The lures came from malicious JavaScript injected into site main pages, referencing a script at columbnezhjdq[.]com named goolgetagmanager.js, which ran browser environment checks before presenting staged verification prompts [3]. The injected script was consistent across incidents, but the _cb query parameter varied by site [4]. Victims were told to paste a PowerShell command into Windows Terminal [5].
What that command starts is the part worth reading twice. It triggered an MSI-based staging chain that wrote command-line and PowerShell components into the user's AppData directory [6]. The MSI executed two embedded scripts, november85.cmd and Griffin20.ps1 [7]. Those used winget.exe, the native Windows package manager, to download and install the Deno runtime, after which deno.exe pulled a remote JavaScript payload from webstizkgao[.]com [8]. According to CTU, this let the operators run code remotely without a traditional malware loader [9].
Deno then acted as orchestrator: further PowerShell scripts, system reconnaissance, and persistence through registry Run keys that invoke JavaScript via a headless conhost.exe process [10]. The remote JavaScript delivered a Python payload, install.pyc, executed through pythonw.exe and retrieved from 162[.]33[.]177[.]16 [11]. Sophos analysts confirmed that payload as an infostealer collecting system information, browser and extension data, cryptocurrency wallet data, and keystrokes, alongside telemetry showing system profiling and anti-analysis behaviour [12][13].
Command and control continued through a scheduled task running deno.exe against a remote script at webstizkgao[.]com [15]. On June 23 that script changed to point at a TryCloudflare-hosted staging URL, with downloaded content written into a new registry key disguised as a Microsoft Edge update [16].
Scale came from the web, not from targeting. CTU identified more than 500 compromised WordPress sites carrying similar injections talking to the same two domains, and assessed that the operators used bulk compromise or injection rather than picking targets [17][19]. Columbnezhjdq[.]com was registered on June 1, 2026, five days after webstizkgao[.]com, which puts the earlier registration around May 27, 2026 [18][20].
Deno's signed distributions arrived in the v2.3 release of May 2025, roughly thirteen months before this campaign, and researchers warned then that it could be abused to execute malicious payloads [14][21][22]. Its ability to retrieve remote code, run from user-writable directories, and execute with broad permissions is what makes it fit for multi-stage delivery [23].
Things to watch: winget installing Deno on hosts with no developer justification; scheduled tasks or Run keys whose command line is deno.exe pointing at an HTTP URL [10][15]; and registry values named to look like Edge update state [16]. Allowlisting that trusts signatures and detection that watches only powershell.exe will see none of it.