r/uBlockOrigin 1d ago

Fixed Comunity website classpad.dev gets merked as ClickFix malware.

Hi, I am a core member of the Hollyhock community wich is focused around classpad II / fx-CP400 / fx-CG50 modding.

The website https://classpad.dev which is run by the Hollyhock comunity gets its installer blocked by uBO's ClickFix protection. We use a common irm https://get.classpad.dev/ | iex as no existing installer infratructure could accommedate our needs of usually but not allways preinstalled dependecies and one time use programms. We do not use WIN + R as that triggers windows defender antivirus but rather opt for the user manually opening powershell.

With recent uBO the copy button ceases to function and a banner gets displayed about a potential ClickFix attack.

Source code of the "installer" is avaiable on GitHub. The source of the program itself is private because of the high potantial for exam mode bypasses wich would hurt the comunity a lot but if access is needed I/we can arange something.

10 Upvotes

14 comments sorted by

4

u/RraaLL uBO Team 1d ago

1

u/QBos07 13h ago

I tried the fix but it sitll gets flagged.

1

u/AchernarB uBO Team 13h ago

I think that in your site's case it is the intended purpose. It's to warn users of a potentially dangerous (for them) command. The filter displays the actual content of the paste to allow the user to manually copy+paste.

4

u/gta721 1d ago

Why don't you use an MSI installer?

4

u/QBos07 1d ago

The program is a flasher and patcher for the calculator firmware we are modding. Most people neither need nor want it installed permamently. That is not something the usual MSI installer (or any other installer framework) support.

2

u/gta721 1d ago

What about a zip folder containing the program's files?

3

u/QBos07 1d ago

Was one of the possible options but there were issues:

  • users trying to run without full extraction
  • antimalware false alarms
  • does not manage dependencies

2

u/RraaLL uBO Team 1d ago

With recent uBO the copy button ceases to function and a banner gets displayed about a potential ClickFix attack.

Isn't the full prompt displayed there and possible to select and copy?

1

u/QBos07 13h ago

Yes the promp is displayed and can be manualy selected and copied

3

u/delightfulsorrow 1d ago

We use a common irm https://get.classpad.dev/ | iex

Something like that is "common" only for one kind of "installer".

3

u/QBos07 1d ago edited 1d ago

If I interpret this as "installer" meaning malware than that is not true. The pattern is older then the ClickFix malwares abusing it. Oldest I can think of is massgrave but other new project like Bun and Deno to name a few are also using it.

EDIT: To add that there is a similar method in linux and sometimes macos using `curl | bash` aswell.

2

u/delightfulsorrow 1d ago

The pattern is older then the ClickFix malwares abusing it.

Similar pattern (getting users to manually download and run malicious code) are a thing since the mid 2000s. ClickFix is just the latest manifestation.

Legit projects using the same methods are what ENABLES that. It trains users to follow such instructions.

To add that there is a similar method in linux and sometimes macos using curl | bash aswell.

It is even older there (before PowerShell and Invoke-RestMethod, Windows didn't have the required tools onboard.) But that doesn't make it better.

0

u/_Archimage_ 1d ago

it's a widespread bug. I'm getting from a lot of websites. Something is wrong on the ublock code.

1

u/AchernarB uBO Team 1d ago edited 1d ago

It was a filter too broad. It has already been fixed. Give uBO the time to update the list.

See https://www.reddit.com/r/uBlockOrigin/comments/1w3sc2v/bad_clickflix_filter_matching_all_clipboards/