PasteSentry

Act calmly, but act now

Did a fake CAPTCHA put a command on your clipboard?

Fake verification pages use a technique often called ClickFix: they tell you to open a system tool, paste a command, and run it. In this attack pattern, running the instructed command is the primary risk; the fake page may present other risks too.

If you copied it but did not run it

Do not paste the command into Run, PowerShell, Command Prompt, Terminal, or another system tool. Close the page and copy a harmless sentence to replace the clipboard contents. Copying is not the same as executing, but this page cannot confirm what else happened on your device.

If you ran the command

  1. Stop signing in or entering passwords on that device. The command may have installed software that records or steals information.
  2. Disconnect the device from Wi-Fi and Ethernet. If it belongs to an employer or school, contact its IT or security team immediately and follow their incident process.
  3. Update trusted security software and run a full scan. Microsoft documents both a full scan and Microsoft Defender Offline scan. If threats persist or scans fail, use Microsoft's malware detection and removal guidance or a trusted professional.
  4. Use a separate clean device for important accounts. Change passwords—starting with email, financial, cloud, and work accounts—sign out unknown sessions, and enable multi-factor authentication. Do not type replacement passwords on the affected device until it is believed clean.
  5. Monitor and report. Review important accounts for unfamiliar activity. Report the scam through the relevant cybercrime or consumer-protection channel in your country and contact financial providers promptly if payment or banking information may be exposed.

PasteSentry cannot clean an infected device, cannot reverse an executed command, cannot confirm whether compromise occurred, and cannot guarantee recovery. It is preventive browser protection for known website clipboard-writing paths, not antivirus or an incident-response service.

For background on the attack, read the fake CAPTCHA guide. To see the extension's browser warning without executing anything, use the harmless test page.