r/uBlockOrigin • u/QBos07 • 1d ago
Fixed Comunity website classpad.dev gets merked as ClickFix malware.
Hi, I am a core member of the Hollyhock community wich is focused around classpad II / fx-CP400 / fx-CG50 modding.
The website https://classpad.dev which is run by the Hollyhock comunity gets its installer blocked by uBO's ClickFix protection. We use a common irm https://get.classpad.dev/ | iex as no existing installer infratructure could accommedate our needs of usually but not allways preinstalled dependecies and one time use programms. We do not use WIN + R as that triggers windows defender antivirus but rather opt for the user manually opening powershell.
With recent uBO the copy button ceases to function and a banner gets displayed about a potential ClickFix attack.
Source code of the "installer" is avaiable on GitHub. The source of the program itself is private because of the high potantial for exam mode bypasses wich would hurt the comunity a lot but if access is needed I/we can arange something.
4
u/gta721 1d ago
Why don't you use an MSI installer?
3
u/delightfulsorrow 1d ago
We use a common irm https://get.classpad.dev/ | iex
Something like that is "common" only for one kind of "installer".
3
u/QBos07 1d ago edited 1d ago
If I interpret this as "installer" meaning malware than that is not true. The pattern is older then the ClickFix malwares abusing it. Oldest I can think of is massgrave but other new project like Bun and Deno to name a few are also using it.
EDIT: To add that there is a similar method in linux and sometimes macos using `curl | bash` aswell.
2
u/delightfulsorrow 1d ago
The pattern is older then the ClickFix malwares abusing it.
Similar pattern (getting users to manually download and run malicious code) are a thing since the mid 2000s. ClickFix is just the latest manifestation.
Legit projects using the same methods are what ENABLES that. It trains users to follow such instructions.
To add that there is a similar method in linux and sometimes macos using
curl | bashaswell.It is even older there (before PowerShell and Invoke-RestMethod, Windows didn't have the required tools onboard.) But that doesn't make it better.
0
u/_Archimage_ 1d ago
it's a widespread bug. I'm getting from a lot of websites. Something is wrong on the ublock code.
1
u/AchernarB uBO Team 1d ago edited 1d ago
It was a filter too broad. It has already been fixed. Give uBO the time to update the list.
See https://www.reddit.com/r/uBlockOrigin/comments/1w3sc2v/bad_clickflix_filter_matching_all_clipboards/
4
u/RraaLL uBO Team 1d ago
You can check if this also resolves the issue on your side: https://www.reddit.com/r/uBlockOrigin/comments/1w3sc2v/bad_clickflix_filter_matching_all_clipboards/