security1 distinct publisher
ClickFix operators install the signed Deno runtime to run their remote JavaScript
Sophos says a June 2026 campaign used winget to install the Deno runtime on victim machines, then used deno.exe to fetch, run and persist remote JavaScript ending in a Python infostealer.
Publishers:nakedsecurity.sophos.com
Reality
- Evidence70
- Adoption63
- Hype gap+6
- Incentives62
- Confidence65