FBI director's Based Apparel site has been spotted hosting a 'ClickFix' attack

Hacker News Top News

Summary

BasedApparel.com, an apparel site co-founded by FBI director Kash Patel, was found hosting a ClickFix attack that tricks macOS users into executing a malicious command via Terminal, potentially stealing credentials and cryptocurrency wallet data.

No content available
Original Article
View Cached Full Text

Cached at: 05/23/26, 03:28 AM

# Kash Patel's Apparel Site Is Trying To Trick Visitors Into Installing Malware Source: [https://www.pcmag.com/news/kash-patels-apparel-site-is-trying-to-trick-visitors-into-installing-malware](https://www.pcmag.com/news/kash-patels-apparel-site-is-trying-to-trick-visitors-into-installing-malware) An apparel site from FBI director Kash Patel has been spotted trying to trick macOS users into installing malware\. The site, BasedApparel\.com, is part of a merchandise brand that Patel co\-created with Andrew Ollis prior to becoming FBI director under the Trump administration\. On Thursday, a user based in Portugal[spotted](https://x.com/dm4uz3/status/2057502403151212681)the online shop hosting a “[ClickFix](https://www.pcmag.com/news/this-malware-trap-targets-mac-users-looking-for-tech-help-more-disk-space)”\-style attack that tries to dupe unsuspecting users into running a malicious command on their Mac computers\. The attack seems to work as the user visits BasedApparel\.com; a victim will encounter the site showing a page pretending to come from Cloudflare, which powers “Verify you are human” CAPTCHA tests and offers DDoS protection\. The fake Cloudflare page will show a warning saying “Unusual Web Traffic Detected,” while also requiring the user to verify that they’re human\. But to do so, the page posts some unusual instructions that call for the user to open Terminal, a built\-in utility in macOS that can execute programs\. ![the attack](data:image/svg+xml,%3Csvg%20xmlns='http://www.w3.org/2000/svg'%20viewBox='0%200%20768%20432'%3E%3Crect%20fill='%23f7f7f7'%20/%3E%3C/svg%3E)\(PCMag\) The user is then told to click the “Copy" button on the page to copy the command “I am not a robot: Cloudflare Verification ID: 801470\." But in reality, clicking the button will actually copy a much longer obfuscated text that looks like gibberish, although it's actually a hidden command\. ![the copied command](data:image/svg+xml,%3Csvg%20xmlns='http://www.w3.org/2000/svg'%20viewBox='0%200%20768%20432'%3E%3Crect%20fill='%23f7f7f7'%20/%3E%3C/svg%3E)The actual copied command when you click the copy button\. \(PCMag\) The user is then told to paste and run the command in Terminal, thus executing the instructions without realizing the danger\. The hidden command will decode, and fetch a shell script containing a list of commands from the hacker\-controlled web domain\. PCMag encountered the attack while navigating BasedApparel\.com on a MacBook, although we were only able to trigger the fake Cloudflare page once over the Chrome browser\. > [This Tweet is currently unavailable\. It might be loading or has been removed\.](https://twitter.com/dm4uz3/status/2057522739116724564) The user on X who flagged the threat, “debbie," told PCMag she encountered the attack after reading an[article](https://www.theatlantic.com/politics/2026/05/kash-patel-fbi-bourbon/687066/)in*The Atlantic*about Patel that linked to the Based Apparel site\. “The ClickFix attack just kinda popped up when I was browsing it,” Debbie said in an email\. “I took a quick look and it's just a classic infostealer, wrapped twice in base64 \(binary\-to\-text encoding\)\. It's interesting that it's written in Applescript though\.” debbie, who described herself as a “big nerd,” managed to retrieve the malicious shell script payload, which we ran through VirusTotal\. The payload was[flagged](https://www.virustotal.com/gui/file/d7cda8f1aa6db03f28db359eea23edb5f15b23c6dd0279cbe70bc6c6a64f3ef2/detection)by 27 antivirus engines as malicious, classifying it as Trojan and infostealer\. The attack seems to work by spanning various instructions that if run through macOS’s Terminal utility could steal stored credentials from Chromium\-based browsers along with data from cryptocurrency wallets, placing them into a zip archive then sent to a hacker\-controlled domain\. The attack suggests a hacker compromised some portion of BasedApparel\.com when the ClickFix threat has remained[pervasive](https://www.pcmag.com/news/this-windows-update-screen-is-actually-a-hackers-trap)in recent years, fooling less tech\-savvy users\. Security researchers have[warned](https://www.bitdefender.com/en-us/blog/hotforsecurity/clickfix-compromised-wordpress-sites-vidar-stealer-australia)that the hackers behind ClickFix schemes have been circulating their attacks by stealing the login credentials for legitimate websites, tampering with exposed admin panels, or hitting vulnerable plugins\. Based Apparel didn’t immediately respond to a request for comment\. But the attack is a reminder to be vigilant around pop\-ups and other scareware tactics\. Apple recently[introduced](https://x.com/ClassicII_MrMac/status/2036797948911141129?ref_src=twsrc%5Etfw%7Ctwcamp%5Etweetembed%7Ctwterm%5E2036797948911141129%7Ctwgr%5E482f8db6b8f53ced949d9fbd4b25997b71153ee3%7Ctwcon%5Es1_&ref_url=https%3A%2F%2Fwww.pcmag.com%2Fnews%2Fthis-malware-trap-targets-mac-users-looking-for-tech-help-more-disk-space)a safeguard in macOS Tahoe 26\.4 that can stop and warn users against running copied\-and\-pasted commands into the Terminal utility, citing the potential of malware\. ## About Our Expert ![Michael Kan](https://i.pcmag.com/imagery/authors/06W4G6A5rmg4LxEffqKnnc6.fit_lim.size_100x100.v1560221550.png) Michael Kan Principal Reporter --- Experience I've been a journalist for over 15 years\. I got my start as a schools and cities reporter in Kansas City and joined PCMag in 2017, where I cover satellite internet services, cybersecurity, PC hardware, and more\. I'm currently based in San Francisco, but previously spent over five years in China, covering the country's technology sector\. Since 2020, I've covered the launch and explosive growth of SpaceX's Starlink satellite internet service, writing 600\+ stories on availability and feature launches, but also the regulatory battles over the expansion of satellite constellations, fights with rival providers like AST SpaceMobile and Amazon, and the effort to expand into satellite\-based mobile service\. I've combed through FCC filings for the latest news and driven to remote corners of California to test Starlink's cellular service\. I also cover cyber threats, from ransomware gangs to the emergence of AI\-based malware\. In 2024 and 2025,[the FTC forced Avast](https://www.pcmag.com/news/did-avast-sell-your-data-heres-how-to-get-a-piece-of-the-ftc-settlement)to pay consumers $16\.5 million for secretly harvesting and selling their personal information to third\-party clients, as revealed in my joint[investigation](https://www.pcmag.com/news/the-cost-of-avasts-free-antivirus-companies-can-spy-on-your-clicks)with Motherboard\. I also cover the PC graphics card market\. Pandemic\-era shortages[led me to camp out](https://www.pcmag.com/news/i-camped-out-at-best-buy-to-get-an-rtx-3000-graphics-card-feel-my-pain)in front of a Best Buy to get an RTX 3000\. I'm now following how the AI\-driven memory shortage is impacting the entire consumer electronics market\. I'm always eager to learn more, so please jump in the comments with feedback and send me tips\. [Read Full Bio](https://www.pcmag.com/authors/michael-kan)

Similar Articles

Websites Can Now Spy on You Through Your Hard Drive

Wired

A new technique called FROST exploits SSD timing side channels in browsers to spy on users' activities, identifying open websites and apps without requiring any interaction beyond visiting a malicious site.

From teen hacker to Iron Dome researcher, this founder raised $28M to fight AI phishing

TechCrunch AI

Ocean, an agentic email security platform built to fight AI-powered phishing attacks, emerged from stealth with $28M in funding led by Lightspeed Venture Partners, and claims its AI analyzes email context to detect fraud. The startup was founded by Shay Shwartz, a former hacker turned cybersecurity expert who worked on Israel's Iron Dome project.

Weekly Update 502

Troy Hunt

Troy Hunt's weekly update discusses how ShinyHunters uses social engineering and vishing to breach major brands, with insights from Mandiant.

Fake OpenAI Privacy Filter on Hugging Face Dropped a Rust Infostealer

Reddit r/ArtificialInteligence

A fake repository impersonating OpenAI's Privacy Filter reached #1 on Hugging Face, downloading over 240,000 times before being removed. The malicious package distributed a Rust-based infostealer that targeted developer credentials, crypto wallets, and browser data.