| ▲ | c0n5pir4cy 2 hours ago | |
So done a much deeper analysis - there is an loader injected at the Wordpress side which triggers a read of a payload from a smart contract on the Ethereum chain. It stores this in localStorage, registers a ServiceWorker etc so it is persistent. It then spins up the ClickFix attack - limited to one time per day. I haven't dug into the payload given by the ClickFix attack yet. For people that have visited while it exists: 1. On Chrome go to chrome://serviceworker-internals search for crookedtimber and unregister the ServiceWorker 2. On Firefox go to about:debugging#/runtime/this-firefox, search for crookedtimber and unregister the ServiceWorker. If you want to be even safer - just clear all local data for CrookedTimber. | ||