Malicious users are exploiting comments on Pastebin to distribute a new ClickFix-style attack, which tricks cryptocurrency users into running malicious JavaScript in their browser, allowing attackers to intercept Bitcoin exchange transactions and redirect funds to wallets they control.
See also: ClickFix attack distributes StealC malware to Windows systems

The campaign relies on social engineering that promises large profits from a supposed arbitrage exploit on Swapzone.io, but instead executes malicious code that modifies the exchange process directly in the victim's browser. It could also be the first known ClickFix attack that uses JavaScript to alter the functionality of a website for malicious purposes.
In the campaign spotted by BleepingComputer, malicious users browse posts on Pastebin and leave comments promoting an alleged cryptocurrency exploit, with a link to a URL at rawtext[.]host. The campaign is widespread, with multiple posts receiving comments in the past week claiming to be “leaked exploit documentation” that allows users to earn $13,000 in 2 days.
The link in the comment redirects to a Google Docs page titled “Swapzone.io – ChangeNOW Profit Method,” which claims to be a guide describing a method for exploiting arbitrage opportunities for higher returns. The fake guide states that “ChangeNOW still has an older backend node connected to the Swapzone partner API. In the current ChangeNOW, this node is no longer used for public exchanges.”
He continues, “However, when accessed via Swapzone, the rate calculation goes through Node v1.9 for some BTC pairs. This old node applies a different conversion formula for BTC to ANY, resulting in ~38% higher than expected returns.”
See also: New ClickFix attacks infect systems with LummaStealer

At any given time, these documents typically show between 1 and 5 active viewers, indicating that the scam is in circulation. The fake guide provides instructions to visit Swapzone.io and manually load a Bitcoin node by running JavaScript directly in their browser’s address bar. The instructions tell victims to visit a URL in paste[.]sh and copy a JavaScript snippet hosted on the page.
The guide then instructs the reader to return to the SwapZone tab, click on the address bar, type javascript: and then paste the code. Once the code has been pasted into the address, it tells them to press Enter on the keyboard to run it. This technique takes advantage of the browser's 'javascript:' URI feature, which allows users to execute JavaScript from the address on the currently loaded web page.
By convincing victims to run this code on Swapzone.io, attackers can manipulate the page and change the exchange process. BleepingComputer’s analysis of the malicious script hosted on paste[.]sh shows that it loads a secondary payload from https://rawtext[.]host/raw?btulo3. This heavily disguised script is injected directly into the Swapzone page, replacing the legitimate Next.js script used to manage Bitcoin exchanges to hijack the exchange interface.
The malicious script includes embedded Bitcoin addresses, which are randomly selected and inserted into the exchange process, replacing the legitimate deposit address generated by the exchange. Because the code is executed within the Swapzone.io session, victims see a legitimate interface but end up copying and sending funds to Bitcoin wallets controlled by the attackers.
See also: Expansion of ClickFix attacks using fake CAPTCHAs

In addition to replacing the deposit address, the script modifies the displayed exchange rates and bid values.
Source: bleepingcomputer
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
