Gizmodo site compromise served ClickFix malware prompts to readers through a hijacked account

Gizmodo readers were briefly exposed to fake verification prompts on the news site after a compromised account was used to inject malicious code into article pages. The attack delivered ClickFix social-engineering lures that tried to make users run commands locally; according to reporting and researcher analysis, the Windows flow attempted to install NetSupport RAT, a remote-access trojan, while the macOS payload appeared misconfigured and did not execute cleanly.
Why it matters: Anyone who followed the prompt on a Windows device may have installed remote-access malware that can steal files or pull down more malicious tools. Affected users should check for suspicious commands or downloads, run endpoint scans, and site operators should review account security and script-injection controls.

Sources

Gizmodo readers hit with ClickFix malware prompts after account compromise
2026.06.22 100% relevant
This article establishes a distinct incident: a compromise of Gizmodo that was used to serve ClickFix malware lures to site visitors, rather than a generic report on the ClickFix technique.
← Back to all stories