Kash Patel's 'BasedApparel' website is apparently hosting ClickFix malware
- Researcher finds Based Apparel site serving a macOS ClickFix infostealer disguised as a Cloudflare CAPTCHA check
- Victims were tricked into pasting malicious Applescript commands in Terminal, with VirusTotal flagging the malware as a commodity Trojan/infostealer
- The site, built on WordPress/WooCommerce and Ghost CMS, was taken offline after disclosure, linking the incident to broader Ghost CMS exploitation in ongoing ClickFix campaigns
Based Apparel, an American online clothing company selling patriotic, conservative, and pro–free speech-themed merchandise, was seemingly compromised and used to serve malware through the ClickFix technique - but only macOS users were targeted.
A researcher with the alias ‘debbie’ disclosed her findings to PC Mag, before sharing video proof on X, after saying she read online about Based Apparel being co-founded by FBI Director Kash Patel and decided to take a closer look.
“The ClickFix attack just kinda popped up when I was browsing it,” Debbie said in an...
Copyright of this story solely belongs to techradar.com. To see the full text click HERE