#clipboard-hijacking
Like, yeah, to some extent there's always the chance for a specific app to be doing horrible things; see, eg, TikTok capturing the clipboard contents as you scroll or "calculator" apps that are hijacking your device to mine cryptocurrency or be a botnet node, yadda.
February 2, 2026 at 2:31 AM
A newly discovered clipboard hijacking operation dubbed 'MassJacker' uses at least 778,531 cryptocurrency wallet addresses to steal digital assets from compromised computers.
MassJacker malware uses 778,000 wallets to steal cryptocurrency
A newly discovered clipboard hijacking operation dubbed 'MassJacker' uses at least 778,531 cryptocurrency wallet addresses to steal digital assets from compromised computers.
www.bleepingcomputer.com
March 11, 2025 at 4:06 PM
A new malware-as-a-service called CrystalRAT is being promoted on Telegram, offering remote access, data theft, keylogging, and clipboard hijacking capabilities.
New CrystalRAT malware adds RAT, stealer and prankware features
A new malware-as-a-service called CrystalRAT is being promoted on Telegram, offering remote access, data theft, keylogging, and clipboard hijacking capabilities.
www.bleepingcomputer.com
April 1, 2026 at 11:17 PM
Sounds like there’s probably JavaScript or something hijacking the clipboard. Maybe it only fires once and that’s why it works the 2nd time
April 2, 2025 at 6:41 PM
Microsoft Threat Intelligence reports that a new variant of the XCSSET macOS malware has been detected in limited attacks, incorporating several new features, including enhanced browser targeting, clipboard hijacking, and improved persistence mechanisms.
Microsoft warns of new XCSSET macOS malware variant targeting Xcode devs
Microsoft Threat Intelligence reports that a new variant of the XCSSET macOS malware has been detected in limited attacks, incorporating several new features, including enhanced browser targeting, clipboard hijacking, and improved persistence mechanisms.
www.bleepingcomputer.com
September 25, 2025 at 10:49 PM
third-party.com, a common placeholder in dev docs and AI agent configs, is now serving clipboard-hijacking malware. 1,700+ GitHub repos reference it. Static scans won't catch it. https://thehackernews.com/2026/09/placeholder-third-partycom-referenced.html
September 25, 2026 at 6:06 AM
Aus dem Feed: ⟪ Cyberkriminelle kapern tausende vertrauenswürdige Webseiten für DriveSurge-Angriffe ⟫ https://www.it-daily.net/shortnews/drivesurge-angriffe-webseiten | #medien #design
➔ „Die Kampagne DriveSurge nutzt zTDS, FakeUpdates und Clipboard-Hijacking, um Besucher gekaperter …
DriveSurge-Angriffe: Cyberkriminelle kapern Webseiten
Die Kampagne DriveSurge nutzt zTDS, FakeUpdates und Clipboard-Hijacking, um Besucher gekaperter Webseiten unbemerkt mit Schadsoftware zu infizieren.
www.it-daily.net
June 8, 2026 at 10:58 AM
📋 Paste Without Attachment in Claude 💥

🤚 Stop Claude from hijacking your clipboard - paste long text as text, not attachment!

gist.github.com/intellectro...
0.README.md
GitHub Gist: instantly share code, notes, and snippets.
gist.github.com
December 8, 2025 at 3:57 PM
Opera has introduced Paste Protect, a feature to prevent clipboard hijacking and malicious code injection attacks. It alerts users when harmful content is copied. It's currently enabled by default for Opera One users on Early Bird mode.
alternativeto.net/news/2026/7...
July 3, 2026 at 11:58 AM
Michael Haag has very cool threat intel on ClickFix campaigns @ mhaggis.github.io/ClickGrab/

He also just gave a very cool talk on it at BSides Boulder.
June 21, 2026 at 5:22 PM
This new XCSSET variant improves browser targeting, clipboard hijacking, and persistence mechanisms. It employs sophisticated encryption and obfuscation techniques, uses run-only compiled AppleScripts for stealth, and expands data exfiltration capabilities.
September 25, 2025 at 3:09 PM
⚠️ HiddenGh0st, Winos & kkRAT leveraged via SEO and GitHub Pages

Attackers used SEO poisoning + lookalike domains + GitHub Pages to distribute RATs targeting Chinese speakers. Features include malicious installers, DLL sideloading, AV bypass, C2 comms, clipboard hijacking, crypto wallet theft.
September 16, 2025 at 7:19 AM
Microsoft warns of new XCSSET macOS malware variant targeting Xcode devs
Microsoft warns of new XCSSET macOS malware variant targeting Xcode devs
Microsoft Threat Intelligence reports that a new variant of the XCSSET macOS malware has been detected in limited attacks, incorporating several new features, including enhanced browser targeting, clipboard hijacking, and improved persistence mechanisms.
www.bleepingcomputer.com
September 25, 2025 at 11:10 PM
Time for web browsers to crack down on sites putting data in the clipboard.

THIS IS NOT A REAL CAPTCHA. IT'S A SCAM TELLING YOU TO INSTALL A VIRUS ON YOUR COMPUTER BY QUIETLY HIJACKING THE "CUT"/"COPY" FUNCTION AND THEN TELLING YOU TO "PASTE" AND RUN IT.
Excuse me, what's going on with captcha?
June 20, 2026 at 1:55 AM
June 27, 2025 at 7:13 PM
Beware! New "MassJacker" malware targets users of pirated software, hijacking crypto funds by replacing wallet addresses in your clipboard. Over 770,000 addresses already affected! Protect yourself and avoid pirated software. #cryptocurrency #malware #security #piracy

#blockchain #news
March 15, 2025 at 10:14 AM
2025-09-03 (Wednesday): #Kongtuke fake CAPTCHA page leads to #ClickFix style script for #LummaStealer

A #pcap of the infection traffic, the associated malware, and IOCs are at www.malware-traffic-analysis.net/2025/09/03/i...
September 3, 2025 at 6:13 PM
Notícia da BleepingComputer

"Malware MassJacker utiliza 778.000 carteiras para roubar criptomoeda" #bolhasec
MassJacker malware uses 778,000 wallets to steal cryptocurrency
A newly discovered clipboard hijacking operation dubbed 'MassJacker' uses at least 778,531 cryptocurrency wallet addresses to steal digital assets from compromised computers.
www.bleepingcomputer.com
April 18, 2025 at 2:30 AM
New Linux Bug Could Lead to User Password Leaks and Clipboard Hijacking
New Linux Bug Could Lead to User Password Leaks and Clipboard Hijacking
A new Linux vulnerability puts user passwords at risk. It exploits the "wall" command to potentially leak passwords on Ubuntu & Debian systems.
thehackernews.com
March 29, 2024 at 11:08 AM
They probably justify it with preventing clipboard hijacking attacks. Which is valid, but not the best way to go.

My bank allows pasting and then replaces last digit with an asterisk, so I have to look up just one digit. But at the same time I would probably see that the whole number is different.
November 22, 2024 at 11:10 AM
Microsoft finds USB worm that steals cryptocurrency through clipboard hijacking and Tor thenextweb.com/news/microso...
Microsoft finds USB worm that steals cryptocurrency through clipboard hijacking and Tor
Microsoft discovered a self-spreading USB worm active since February that monitors clipboards for crypto wallets and routes stolen data through Tor.
thenextweb.com
June 21, 2026 at 7:20 AM
I break down the mechanics of the clipboard hijacking technique and why standard firewalls often miss it. Check it out.
November 27, 2025 at 6:31 AM