Kash Patel’s ‘BasedApparel’ Website Apparently Hosts ClickFix Malware



  • Researcher finds Based Apparel site offering macOS ClickFix infostealer disguised as Cloudflare CAPTCHA verification
  • Victims were tricked into pasting malicious Applescript commands into Terminal, and VirusTotal flagged the malware as a basic trojan/data stealer.
  • The site, built on WordPress/WooCommerce and Ghost CMS, was taken offline following the disclosure, linking the incident to a broader exploitation of Ghost CMS in ongoing ClickFix campaigns.

Based Apparel, an American online clothing company that sells products with patriotic, conservative, and pro-free speech themes, was apparently compromised and used to distribute malware via the ClickFix technique, but only macOS users were targeted.

A researcher with the alias ‘debbie’ revealed her findings to PC Magazinebefore sharing video evidence about X, after saying he read online about FBI Director Kash Patel’s co-founding of Based Apparel and decided to take a closer look.

Leave a Comment

Your email address will not be published. Required fields are marked *