STPI Website Under Cybersecurity Alert After Fake Cloudflare Verification Page Attempts to Trigger Malicious Windows Terminal Commands
STPI website malware alert: Fake Cloudflare verification reportedly targets Windows users with malicious Terminal commands in a TerminalFix-style cyber attack, raising cybersecurity concerns.
A website linked to the Software Technology Parks of India (STPI), a Government of India organisation, has reportedly been found displaying a fake Cloudflare verification page that could trick visitors into running a malicious command on their Windows computers.
The suspicious activity was identified on the ananta.stpi.in subdomain by cybersecurity researcher and red teamer Vibhum Dubey. He reported the issue to STPI and CERT-In, India's Computer Emergency Response Team.
STPI provides technology and cloud infrastructure services to Indian companies, startups, developers and other organisations. The reported presence of a malware-related attack on a government-linked website has therefore raised concerns about the potential risks to people visiting the portal.
The malicious page is designed to resemble the familiar Cloudflare “Verify you are human” screen that users commonly encounter when accessing websites. However, the fake verification page includes an unusual instruction that it asks visitors to open *Windows Terminal*, paste a command and press Enter. The page can also place a malicious string in the user's clipboard without making the action obvious.
The copied content contains a URL. If a visitor pastes it into Windows Terminal and executes it, the command can send a request to infrastructure controlled by an attacker.
Dubey did not execute the command himself. However, security checks found that the destination associated with it had been flagged as malicious by multiple security vendors. At the time of the analysis, 17 security engines on VirusTotal reportedly detected the destination as malicious.
The technique resembles attacks commonly referred to as TerminalFix and ClickFix. These campaigns use fake verification screens or similar prompts to persuade users to copy and execute commands on their own computers.
Rather than installing malware directly through the browser, the attack relies on the victim following the instructions. This approach can potentially help attackers bypass some traditional browser and web-security protections.
The suspicious behaviour was associated with an external JavaScript file loaded from a domain called cdn.quickdelivr.com. The domain was reportedly registered recently and uses a name that closely resembles the legitimate jsDelivr content delivery network.
The script was heavily obfuscated and appeared to communicate with external infrastructure. According to the researcher, it also assigned unique identifiers to visitors, suggesting that some form of visitor tracking may have been taking place.
The fake verification page reportedly disappeared temporarily before appearing again. The continued presence of the external script raised concerns that the underlying malware delivery mechanism may not have been completely removed.
The researcher also identified a possible WordPress configuration weakness that could expose an administrator username. However, there is no confirmation that the weakness was actually used to gain access to the website. CERT-In acknowledged the report and said it was taking appropriate action with the concerned authority.
For users, the most important warning is simple that never copy and execute commands in Windows Terminal simply because a website asks you to complete a “human verification” check. A legitimate Cloudflare verification process should not normally require visitors to manually run unknown commands on their computers.
Information referenced in this article is from CSO Online