ClickFix: The Fake Cloudflare Captcha Scam
ClickFix fake captcha prompts trick Windows and Mac users into installing malware. What to do if you ran the command, and how to clean it off WordPress.
9 min read · 29 September 2026

If a website asked you to prove you are human by pressing Windows + R, or by opening Terminal on a Mac, then pasting something and pressing Enter, it was not a real check. It was ClickFix, a scam that runs on hacked websites and gets visitors to install malware on their own computers. Many of the sites serving it are ordinary small business and community sites running WordPress, and their owners usually have no idea.
We have cleaned ClickFix off several New Zealand websites this year. This guide covers what it looks like, what to do if you followed the steps, and how to get it off your site for good.
What a ClickFix prompt looks like
The page shows what looks like a Cloudflare or Google reCAPTCHA check, with a "Verify you are human" box to tick. Instead of pictures of traffic lights, you get a short set of instructions. The page checks which computer you are on and gives you the version for it.
On Windows
- Press Windows + R
- Press Ctrl + V
- Press Enter
On a Mac
- Press Command + Space and type Terminal
- Press Command + V
- Press Enter, and type your Mac password if asked
Mac users are not safe from this. The Mac versions are newer and spreading fast, and they often ask for your login password as part of the "verification", which hands the malware everything it needs. Some versions of both skip the captcha and pretend to fix a browser error, a missing font or a broken video instead.
A real captcha never asks you to use your keyboard outside the browser. Cloudflare and Google will never ask you to open the Run box, Terminal or anything else, or to type your computer password.
What the command does
When you ticked the box, the page quietly copied a command to your clipboard. Pasting it into the Run box or Terminal runs it on your computer with your own permissions, so your antivirus sees you doing it. It usually downloads an infostealer: malware that copies the passwords saved in your browser and your logged-in sessions, then sends them to the attacker within minutes. On a Mac, the common ones also take the passwords stored in your Keychain, using the password you typed. Some versions take crypto wallets or install remote access tools as well.
The stolen sessions are the part people underestimate. A session is what keeps you logged in, and with a copy of it someone can open your email or social media as you, often without needing your password or your two-factor code. The stolen logins also get used later. It is common for a business to have its Instagram or Facebook taken over weeks or months after someone ran the command, with the account then used to post crypto scams and message followers.
If you ran the command
Assume everything on that computer has been taken, and work through this in order:
- Disconnect the computer from the internet and stop using it for anything that needs a login.
- On a different device you trust, change your email password first, then banking, social media and anything else that was saved in the browser.
- In each account, log out of all other sessions. Most services have this under their security settings, and it is what makes a stolen session useless.
- Turn on two-factor login everywhere it is offered, ideally with an authenticator app rather than text messages.
- Check your email for forwarding rules or filters you did not set up. Attackers add them so they can keep reading your mail after you change the password.
- Have the computer wiped and Windows or macOS reinstalled. Antivirus removing one file does not prove the machine is clean.
- On a Mac, change your Mac login password too, and treat everything in your Keychain and iCloud Keychain as exposed.
- If it is a work computer, tell your IT provider straight away. If banking details could be involved, call your bank.
You can also report it to the National Cyber Security Centre, which now includes CERT NZ, at ncsc.govt.nz.
Why site owners often cannot see it
If your own website is serving ClickFix, you may never see the prompt yourself. The scripts are usually cloaked: they show only to first-time visitors on desktop computers, hide from logged-in administrators and from Google, and often show once per visitor before going quiet. The first sign is often a customer or staff member saying your site asked them to press Windows + R or open Terminal.
Things worth checking:
- Visitors mentioning a Cloudflare or captcha check you never set up
- Security warnings in Google Search Console, or Chrome showing a red "dangerous site" screen
- Administrator accounts in WordPress that you do not recognise
- Plugins or themes you did not install, often named like a real one or ending in a string of numbers
- Your host or a security team emailing to say your site is serving malware
How it gets onto a WordPress site
The fake captcha is the end of an attack, not the start. Attackers usually get in with a stolen or guessed administrator password, or through an out-of-date plugin with a known hole. Once they are in, the pattern is fairly consistent:
- Extra administrator accounts are created so they can get back in
- Fake plugins or themes are installed that look legitimate and hide backdoors
- The ClickFix script is injected into the database, a theme file or a must-use plugin
- The actual payload is loaded from outside your site, sometimes from a blockchain smart contract, so it can be changed without touching your site again
That is why a cleanup that only removes the visible script tends to fail. The backdoors stay behind and the site is reinfected within days. We have also seen one infected site spread to others sharing the same hosting account.
How we clean it up
When we clean a ClickFix infection, the order matters:
- Take a copy of the site and its logs first, so there is a record of what happened
- Compare every WordPress core file against the official release, and check plugins against clean copies
- Search the files and the database for injected scripts and backdoors, including the places automated scanners miss
- Remove rogue administrator accounts, fake plugins and scheduled tasks
- Reset every password, log out every session and turn on two-factor login for all users
- Update WordPress, plugins and themes, and remove anything that is not used
- Put a firewall in front of the site and ask Google to review any warning
- Recheck the site on plain URLs over the following days, because cloaked malware can look clean on a single visit
If a site has been hacked more than once, we will tell you honestly whether it is worth cleaning again or better to rebuild.
Keeping it from happening again
Most of the ClickFix sites we have cleaned had the same gaps: shared administrator logins, no two-factor, plugins that had not been updated in months, and hosting where nobody was watching. Closing those does more than any security plugin. Our managed hosting takes care of the firewall, updates and monitoring so it is not left to chance.
Need a hand?
If your site is showing a fake captcha, or someone has told you it asked them to press Windows + R or open Terminal, we can clean it up and lock it down. Get in touch and we will look at it straight away.


