How to tell
Is this CAPTCHA a virus?
Written by Antonio Radu. Something wrong or out of date? corrections@clickfixreport.com
If you have not pasted anything, nothing has happened to your computer. A lure page carries no exploit — starting a program on your machine unasked would take a vulnerability in your browser, and this attack exists precisely because it does not have one. Writing to your clipboard is the limit of what it can do on its own.
If you have already pasted, go straight to the Windows or macOS steps. The first few minutes matter; everything below can wait.
If you clicked but did not paste
- Close the tab.
- Copy some ordinary text — a word from any document — so your clipboard no longer holds the command. Do not paste it anywhere to inspect it first.
- Do not open a Run box or Terminal for the rest of the session. Accidental pastes happen minutes later, out of habit, while the clipboard still holds it.
- If it happened on a site you normally use, tell its owner. They are very likely compromised and unaware.
- If it happened on a work device, tell your security team anyway. Your click is not the interesting part; the page reaching your network is.
If you are not sure whether you pasted — you remember pressing keys but not what happened next — treat it as though you did.
What a real check looks like
Three providers cover almost every human-verification box on the web, and all three behave the same way from your side. Cloudflare Turnstile is a small branded box that very often verifies with no interaction at all. Google reCAPTCHA is an “I’m not a robot” checkbox, sometimes followed by a grid of photographs; the newest version is invisible and asks nothing. hCaptcha is a checkbox and, if it is unsure, a similar image grid.
Others exist — a slider you drag, a button you press and hold, distorted text you retype, an audio alternative. The list is not the point, because in every case the interaction begins and ends inside the web page. Typing characters into a box on the page is normal. Being told to press a key combination, open a program, or carry something off to paste elsewhere never is.
Five questions that settle it
You do not need to identify the malware. You only need to answer these:
Does it ask you to press a key combination?
Being told to hold Windows and press R, or to press Command and Space, is the single clearest tell — no genuine check has ever asked for it. On Windows the target is the Run box or a PowerShell window; on macOS it is Terminal, usually opened through Spotlight. This one question resolves nearly every case.
Does it want something to happen outside the browser?
A terminal, a Run box, a settings panel, a downloaded file. Real checks stay inside the page. Some versions of this lure are styled as a browser or system update rather than a CAPTCHA, and the same answer applies.
Is there a code, ID or key for you to paste somewhere?
The instructions call it a verification ID, a cache key, a reference number or a “ray ID”, because calling it a code makes pasting it feel clerical. It is a command. Note that the page never shows you the text: the tick you pressed to confirm you are human is what silently placed it on your clipboard, and that is the part almost everyone misses.
Did confirming you are human create more work?
A real check gets out of your way once it is satisfied. It does not reward a correct answer with a set of instructions, and it does not hurry you with a countdown or a claim that the check has already failed once.
Would you be doing this if the page had asked plainly?
Strip the security framing and read the actual request: “run this command on your computer, from a website you did not choose to trust”. Framing is the only thing this attack has.
If you did paste
Do not spend time working out which malware it was. Start with the steps for your system; they are ordered so the most valuable actions come first.
Nothing on this page asks you to run a command, download a fix, or paste anything into a terminal — and it never will. Any site that offers to solve this for you and then tells you to paste a command is the same attack a second time.