100+ Compromised Websites Use Fake Cloudflare Checks to Deliver LunexStealer
Overview
The Computer Emergency Response Team of Ukraine (CERT-UA) has reported that over 100 websites have been compromised with malicious JavaScript code to distribute LunexStealer, an information-stealing malware. This activity was detected in September 2026 and is linked to a threat group identified as UAC-0277. The malware targets users by masquerading as legitimate Cloudflare checks, tricking them into downloading the malicious software. This incident raises concerns for both website owners and users, as it highlights the ongoing risks associated with compromised web environments. Users who visit these affected sites may unknowingly expose their personal information to cybercriminals, making it crucial for individuals to be vigilant about the websites they access.
Key Takeaways
- Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
- Affected Systems: Compromised websites serving LunexStealer.
- Action Required: Website owners should remove the malicious JavaScript code and secure their sites against further compromises.
- Timeline: Ongoing since September 2026
Original Article Summary
The Computer Emergency Response Team of Ukraine (CERT-UA) has identified more than 100 compromised websites that have been injected with malicious JavaScript to serve an information-stealing malware called LunexStealer (aka Psychedelic Stealer). The activity, which was observed by the agency in September 2026, has been attributed to a threat cluster dubbed UAC-0277. It did not disclose who the
Impact
Compromised websites serving LunexStealer.
Exploitation Status
This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.
Timeline
Ongoing since September 2026
Remediation
Website owners should remove the malicious JavaScript code and secure their sites against further compromises. Users are advised to avoid visiting unknown or suspicious websites.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to Malware.