FBI DIRECTOR'S APPAREL SITE HOSTS MALWARE ATTACK
SECURITY DESK■ 1 MIN READ
SAT, MAY 23, 2026■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE
The Based Apparel website linked to FBI Director Kash Patel has been identified hosting a ClickFix malware attack, attempting to trick visitors into installing malicious software.
Security researchers discovered the attack vector on the e-commerce site, which uses social engineering tactics common to ClickFix campaigns. These attacks typically display fake system warnings or update prompts, deceiving users into downloading malware.
ClickFix attacks have become increasingly prevalent in 2024, targeting Windows users through compromised websites and malicious ads. The malware often leads to ransomware infections or credential theft.
The discovery raises questions about website security practices and third-party vulnerabilities. It's unclear whether the attack represents a compromise of the site's infrastructure or a supply chain issue.
Based Apparel sells merchandise featuring political messaging. The incident highlights how high-profile websites remain attractive targets for attackers seeking to distribute malware at scale.
No statement has been issued regarding the attack or remediation efforts.
■ SOURCES
► Hacker News■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE
■ MORE FROM THE SECURITY DESK
Cybercriminals have transformed DDoS attacks into a polished, commercialized service complete with pricing tiers, customer support, and reseller programs. The DDoS-as-a-Service market has evolved from basic tools into sophisticated attack platforms.
3H AGO— Industry Desk
Microsoft faced backlash after threatening a security researcher with criminal investigation, reigniting debate over software vulnerability disclosure practices and corporate responsibility.
3H AGO— Security Desk
Google is deploying Device Bound Session Credentials (DBSC) to all Chrome users, a security feature designed to prevent account takeovers by protecting session cookies from theft.
3H AGO— Industry Desk
Dutch authorities have dismantled a major botnet comprising 17 million infected devices and seized over 200 servers hosting the operation at a local provider.
3H AGO— Security Desk