
highMalware
Over 100 Compromised Websites Deploy LunexStealer via Fake Cloudflare Checks
The Computer Emergency Response Team of Ukraine (CERT-UA) has identified a campaign in which more than 100 compromised websites were injected with malicious JavaScript designed to deliver LunexStealer, also known as Psychedelic Stealer. The threat activity, observed in September 2026, has been attributed to the threat cluster UAC-0277. The malicious payload uses fake Cloudflare checks as a delivery mechanism to evade basic security scrutiny. Visitors to the affected sites risk infection that leads to the theft of sensitive information including credentials, personal data, and browser-stored content.
The Hacker News1 min read