5,400 perfectly ordinary websites are showing visitors a fake CAPTCHA
The site was a florist, or a bike shop, or a small manufacturer you found through a search. It has been there for years. It is not a fake. It was simply broken into, and now it shows some of its visitors a box asking them to prove they're human.
Netskope published the figures on 5 September: more than 5,400 compromised websites, mostly WordPress and PrestaShop, with roughly 300 to 400 of them actively serving a payload on any given day and a peak of 536 in a single day in August. Over 2,200 organisations have been touched by it. The clever part is where the malware lives. The script injected into each site fetches its instructions from a smart contract on the BNB Smart Chain testnet, a technique called EtherHiding. It costs the attackers nothing, there is no hosting company to complain to, and only the wallet that deployed the contract can change what it says. Rewrite that one contract and every hacked site starts serving something new.
What the visitor sees is the familiar routine: a verification prompt that asks you to press Windows and R, paste what's on your clipboard, and hit Enter. We wrote about a Windows Terminal version of the same trick last week. The box changes, the demand doesn't. Nothing that genuinely checks whether you're a human has ever needed you to run a command, and no legitimate site will ask. If a page tells you to paste something into Windows to continue, close the tab. It is the whole attack.
If you already did it and want to know what landed, Tendvane's Safety check for unwanted software will list what has quietly installed itself, which is a starting point rather than a cure.