Skip to content
Back to Guavy Wire
Stocks

ClickFix Campaign Injects Malicious JavaScript into Google Sheets

Instruments
GOOGL
Share

A sophisticated cyberattack campaign, dubbed ClickFix, targeted cryptocurrency users by manipulating browser code execution and injecting malicious JavaScript into Google Sheets. The attackers created a fake vulnerability report in Google Docs, which they shared on Telegram, DarkForums, and paste sites.

The lure claimed that an outdated API function at a cryptocurrency swap service could yield a larger payout or loyalty bonus. Targets were instructed to copy code from a paste site and paste it into Chrome's address bar with a javascript: prefix, or install the legitimate Tampermonkey extension and add a supplied userscript.

Once installed, the second-stage payload retrieved obfuscated JavaScript fragments from publicly published Google Sheets, reconstructed the payload, and injected it into the active browser session. The script altered responses, pages, and copied addresses to support the lure's story and made unauthorized changes appear as part of a special exchange feature.

More on Stocks

Disclaimer: Guavy is a data and market intelligence provider, not an investment adviser. The information, signals, and market analysis provided by the Guavy API and related services are for informational purposes only and are not intended as financial advice, investment recommendations, or an endorsement of any particular trading strategy. Trading in volatile markets, including cryptocurrency, carries significant risk and may not be suitable for all investors. Past performance is not indicative of future results. Users should consult with a qualified financial professional before making any investment decisions. Guavy makes no guarantee of trading profits or financial returns.

Market sentiment intelligence for apps, funds & agents

Location

729 55 Ave SW
Calgary AB T2V 0G4
Canada

© 2026 Guavy Inc