top of page

Reddit Ads Led Users to Paste Malicious Commands, Researchers Say

Writer: Andrej Botka
Andrej Botka
2 hours ago
2 min read

A wave of browser-based ploys recently funneled Reddit users to counterfeit pages that coaxed them into executing commands that installed data-stealing malware, security researchers warn. The campaign, tied to so-called ClickFix scams, duped visitors into pasting lines of text into Windows Command Prompt or macOS Terminal, instantly giving attackers access to saved credentials, active sessions and cryptocurrency keys.


The scheme typically begins with a convincing prompt on a web page — sometimes mimicking routine bot checks — that instructs a visitor to copy a short script and paste it into a system shell to “verify” their device. When run, the one-line command pulls and runs code that plants an info stealer. Because the payload runs inside the operating system’s command interpreter, traditional endpoint defenses often miss it, researchers say, making the tactic effective on both Mac and Windows machines.


Investigators report that a recent spread used ads posted from a compromised Reddit account allegedly tied to HBO Max to push the lure. Firms including Hudson Rock and ADAMnetworks documented the activity and members of Reddit’s cybersecurity forum flagged the ads. The hijacked account reportedly distributed advertisements numbering in the hundreds before Reddit disabled it and removed the links. Warner Bros. Discovery did not respond to requests for comment; Reddit confirmed to reporters that it found a breached advertising account and took action but declined to disclose how many users saw or clicked the malicious listings.


ClickFix-style attacks were once uncommon and focused mainly on people hunting quick fixes online. But researchers say the method has scaled up into larger, cross-border operations that exploit users’ unfamiliarity with command-line tools. Security practitioners note that one-line commands are normal for developers, yet atypical for most consumers. Blocking access to terminals across managed Windows environments can blunt the threat, security analyst Kevin Beaumont advised, and macOS users can employ utilities such as BlockBlock to guard against persistent installers.


Digital-safety experts urge simple precautions: don’t paste code from untrusted websites into a shell, double-check URLs before interacting with prompts and keep two-factor authentication and password managers active. If you suspect a machine was compromised, disconnect it from networks, change passwords from a separate device and consult a trusted security professional. Researchers continue to monitor the campaign and are urging ad platforms and site operators to step up controls to prevent similar abuse.

 
 
 

Recent Posts

See All

Comments


Subscribe here to get our latest posts

© 2026 by The StartupsCentral. 

  • X
bottom of page