India’s STPI serves TerminalFix-style attack via fake Cloudflare check (opens in a new tab)
Why readA government-linked Indian domain, ananta.stpi[.]in, was serving a fake Cloudflare check that pastes a command to the clipboard for execution in Windows Terminal.
The page mimics a "Verify you are human" prompt but adds a step telling the visitor to open Windows Terminal and run the clipboard contents, a ClickFix variant using Terminal rather than the Run dialog. Researcher Vibhum Dubey reported it to STPI and CERT-In; CSO confirmed the malicious external JavaScript was still embedded in the page source after the behaviour briefly stopped, suggesting incomplete remediation. Worth noting for anyone whose users trust stpi.in as a legitimate government resource, and a reminder to hunt for Terminal-spawned interpreter activity.
Indicators3
- Domains
ananta[.]stpi[.]incdn[.]quickdelivr[.]comdomaintools[.]com