Fake Cloudflare page on Indian IT agency site pushed terminal commands

A government-linked Indian IT portal served a fake Cloudflare check that tried to get visitors to run a copied command.

CSBadmin
2 Min Read

Visitors to a government-linked Indian tech portal have been met with a bogus Cloudflare check that quietly drops a command onto their clipboard and urges them to paste it into Windows Terminal.

The site belongs to Software Technology Parks of India, a state body backing the country’s IT services and startup scene. Its portals serve technology firms, developers, and public-sector staff, which raises the stakes of any compromise.

The malicious page surfaced on ananta.stpi[.]in, a subdomain the agency runs. Researcher Vibhum Dubey flagged it to STPI and to CERT-In, India’s computer emergency response team. Even after the fake page briefly disappeared, CSO’s own review found the suspicious external script still sitting in the page source, a sign the mechanism had not been dismantled.

The lure copies Cloudflare’s familiar human-verification prompt, then adds a twist: open Windows Terminal, paste what is already on the clipboard, hit Enter. What lands there is a URL that a shell will fetch, pointing at infrastructure the attacker controls. Seventeen security engines flagged the destination on VirusTotal.

“What stood out was that this wasn’t a shady email or a fake website, it was on a government portal,” Dubey said. The trick shifts execution out of the browser and onto the endpoint, where web security controls cannot see it. Microsoft catalogues the pattern as TerminalFix, a relative of ClickFix.

The injected script loaded from cdn[.]quickdelivr[.]com, Dubey found. The domain was less than a week old, apes the legitimate jsDelivr CDN, and shares a Hong Kong server with several other freshly registered names. A separate WordPress misconfiguration on the site, he noted, reveals a valid admin username through its error messages.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.