What happened: the infection vector
UAC-0277, a tracked threat cluster, compromised over 100 websites by injecting malicious JavaScript code into their pages. When visitors arrived at these sites, they encountered what appeared to be a legitimate Cloudflare security check—a page that looks identical to Cloudflare's genuine browser integrity verification. Instead of validating the user's connection, the fake check downloaded and executed LunexStealer, a malware variant designed to extract sensitive information from the infected machine.
The attack was identified in September 2026 by Ukraine's Computer Emergency Response Team (CERT-UA). The malware, also known as Psychedelic Stealer, harvests usernames, passwords, browser history, payment card details and session tokens from victims' browsers and installed applications. By leveraging the trust users place in Cloudflare—a major content delivery network and security provider—the attackers bypassed much of the skepticism a typical "download this file" prompt would trigger.
Why fake Cloudflare pages are so effective
Cloudflare's browser check is a well-known security measure that appears when visiting protected websites during traffic spikes or suspicious activity. Most internet users have seen this page at least once and recognize it as routine. The malware authors exploited this familiarity by reproducing the page's appearance with pixel-perfect accuracy, making it nearly impossible to spot the difference at a glance.
The social engineering component is crucial to the campaign's success. Visitors to compromised sites assume they are being protected, not attacked. They see a familiar security interface, wait for it to load, and proceed. The psychological expectation that security tools are trustworthy makes this attack vector particularly dangerous. Users rarely question or inspect the source of a Cloudflare check because it appears in the expected context: on a website they voluntarily visited.
This technique differs from traditional phishing emails, which ask users to click links or download files from external sources. Here, the malware is delivered within the website itself, making it appear part of the normal browsing experience rather than an external threat.
How JavaScript injection enables the attack
The malware was planted through JavaScript injection—a method in which attackers modify the HTML or JavaScript code of a website after gaining unauthorized access. JavaScript runs directly in the user's browser, giving it the ability to display fake interfaces, capture input and download additional payloads without raising traditional antivirus alarms.
Injected scripts can also read form data, steal cookies (which store session information and login credentials) and execute code that loads further malware onto the system. Because JavaScript executes in the browser context, it often bypasses security software that focuses on executable files and network connections. The fake Cloudflare check serves as the delivery mechanism, and once clicked or interacted with, the script initiates the download and execution of the stealer.
The 100+ compromised sites suggest either a large-scale watering hole campaign or a vulnerability that affected many websites using the same hosting provider or content management system. Websites that fail to monitor for unauthorized code changes or lack Web Application Firewalls (WAF) are particularly vulnerable to this type of injection.
What LunexStealer actually does
LunexStealer is an information-stealing malware (also called an infostealer or stealer) that runs silently on an infected device and exfiltrates sensitive data. Once executed, it typically searches for and copies:
- Saved usernames, passwords and login credentials from browsers
- Session cookies and authentication tokens that provide access to accounts without needing a password
- Credit card and payment information stored in browser autofill
- Two-factor authentication bypass tokens or backup codes
- Files containing private keys or cryptocurrency wallet data
- Browser history, autocomplete suggestions and bookmarks
- Email addresses and contact information
The stolen data is sent to servers controlled by the attackers, who then use the credentials to log into victim accounts, change passwords, reset recovery options or sell the data to other criminal groups. A single compromised password or cookie can unlock access to email, banking, social media and work systems.
How to recognize and avoid infection
Several practical steps reduce the risk of infection during normal web browsing.
- Examine the page URL in the address bar before interacting with any security check, even if it looks legitimate
- Check that the URL begins with https:// and the domain matches the website you intended to visit (not a slightly misspelled variant)
- Hover over links or buttons to see the actual destination URL in the browser's status bar
- If a security check appears unexpectedly or loads slowly, close the page and navigate away
- Keep your browser and operating system fully updated with the latest security patches
- Use a reputable antivirus or endpoint security tool to monitor for suspicious scripts and processes
- Enable browser extensions that block malicious JavaScript and scripts from untrusted sources
- Consider using a VPN or Tor Browser for accessing sensitive sites, as both encrypt traffic and can reduce exposure to injected code
If you believe you have encountered this malware, do not assume your device is secure. Immediately change passwords for all important accounts (email, banking, payment services) using a different device that has not visited the compromised websites. Consider monitoring your financial accounts and credit reports for unauthorized activity.
The broader context: injections and supply-chain compromise
JavaScript injection attacks are part of a larger category of supply-chain compromise in which attackers target widely trusted services or websites to reach many victims at once. Rather than attacking individual users, threat actors compromise the infrastructure that users trust, turning it into a delivery mechanism for malware.
This attack pattern has increased as detection capabilities have improved against traditional malware distribution methods like email attachments and direct executable downloads. Law enforcement and security vendors now monitor malware repositories and suspicious download links more closely. Compromising legitimate websites and hiding malware inside them bypasses much of that scrutiny because the traffic appears legitimate and comes from a trusted domain.
The Ukraine CERT-UA attribution to UAC-0277 indicates this group has demonstrated sophistication in targeting multiple websites and coordinating the injection campaign. Such operations typically require access to a database of vulnerable sites, stolen hosting credentials or a common vulnerability affecting many sites simultaneously. The scale of the campaign (100+ sites) suggests either a vulnerability-driven approach or a compromise of a shared hosting platform or content management system used by many organizations.
Takeaways: vigilance and verification matter
This incident demonstrates that even expected, normal-looking security checks can harbor malware if the website delivering them has been compromised. Attackers are not trying to scare you into clicking; they are trying to make you feel safe. The most effective defense is not perfect skepticism—because that is exhausting and not realistic—but rather a mix of habit and tools.
The habit is simple: before interacting with any security check or authentication page, verify that you are on the correct website by checking the URL. The tools include browser security extensions, VPN software, and modern antivirus products that can detect injected scripts. If you work in a role that manages websites, ensure that your platform monitors for unauthorized code changes and uses a Web Application Firewall to filter malicious JavaScript at the network level. Take five minutes today to verify that your browser updates are current and that you have at least one security extension enabled for sites you visit regularly.
Common questions about this malware campaign
What is the difference between LunexStealer and other stealers like Redline or Racoon?
All infostealers harvest similar categories of data, but they differ in capability, detection evasion, distribution method and the threat group behind them. LunexStealer appears to be distributed primarily through compromised websites, while others rely more on email or social media. The specific variant name is less important than understanding that any stealer malware should trigger immediate action: password changes, account monitoring and security updates.
Can I get infected just by visiting a compromised site, or do I have to click something?
In this campaign, the injection delivers the malware only when you interact with the fake Cloudflare check. However, not all JavaScript injection attacks require user interaction. Some can execute automatically or download malware in the background. This is why keeping your browser and plugins updated is essential, as patches close vulnerabilities that allow automatic exploitation.
If I use Tor Browser or a VPN, am I protected from this attack?
Tor Browser and VPNs encrypt your traffic and mask your IP address, but they do not prevent malware from running on your local device if you click a malicious download. They do reduce your visibility to attackers and add friction to the infection chain, making you a less attractive target. They are one layer of defense, not a complete solution.
How do I know if my website was compromised with this malware?
Check your website logs for unexpected file modifications, unusual traffic patterns or unauthorized access. Use a Web Application Firewall to scan for injected scripts. If you manage a website, subscribe to abuse notifications from your hosting provider and monitor your server's file integrity. If you suspect compromise, contact your hosting provider's security team immediately.
Source: The Hacker News
