logoalt Hacker News

c0n5pir4cytoday at 4:40 PM0 repliesview on HN

So done a much deeper analysis - there is an loader injected at the Wordpress side which triggers a read of a payload from a smart contract on the Ethereum chain. It stores this in localStorage, registers a ServiceWorker etc so it is persistent.

It then spins up the ClickFix attack - limited to one time per day. I haven't dug into the payload given by the ClickFix attack yet.

For people that have visited while it exists:

1. On Chrome go to chrome://serviceworker-internals search for crookedtimber and unregister the ServiceWorker

2. On Firefox go to about:debugging#/runtime/this-firefox, search for crookedtimber and unregister the ServiceWorker.

If you want to be even safer - just clear all local data for CrookedTimber.