jsDelivr virus: why cdn.jsdelivr.net shows up in malware alerts, and what to do if you ran a pasted command

jsDelivr is a legitimate free CDN, not a virus, but criminals publish malware on GitHub and link to it through cdn.jsdelivr.net. In September 2026 URLhaus listed five such files:

  • ClickFix scripts tagged ACRStealer
  • a TerminalFix file
  • a Nezha installer

If you only saw the address in a log, nothing is proven. If a web page made you paste a command into Windows, act now.

Facts checked October 8, 2026. Removal steps tested on Windows 11 (26H2) and checked against Microsoft's and the browser makers' current documentation.

Automatic

Get a free scan and check if your PC is infected.

Fortect finds malware, unwanted programs and the Windows damage they leave behind, and repairs it in one pass.

An automatic scan checks installed programs, startup items and browser extensions for anything that came with a command pasted from a web page that fetched a file from cdn.jsdelivr.net.

Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free.

Do it yourself · free Remove jsDelivr virus (malware served through cdn.jsdelivr.net) yourself 5 steps, about 15 minutes, no software needed.

Start the steps
Timeline of five URLhaus reports for files on cdn.jsdelivr.net in September 2026 with their tags
The five URLhaus reports for cdn.jsdelivr.net, September 2026. There is no screenshot of a site here: the service is a CDN, and our check was a plain request from our server.

JsDelivr virus (malware served through cdn.jsdelivr.net): summary

TypeA legitimate CDN abused to deliver malware: ClickFix scripts tagged ACRStealer, a TerminalFix file and a Nezha agent installer
RiskHigh if you pasted and ran a command from a web page. None if you only saw cdn.jsdelivr.net in a log or a normal website
SymptomsOften none. Accounts opened elsewhere, an update like scheduled task, odd PowerShell or pythonw.exe
How to get rid of itChange passwords and sign out sessions from another device, run Microsoft Defender Offline, remove startup items, reset Windows if unsure
Our check (8 October 2026)Plain request from our server: HTTP 301 to www.jsdelivr.com via Cloudflare. Reported files not requested
PlatformWindows for the ClickFix files; Linux servers for the Nezha installer
Removal

Scan the PC with security software to find and remove the malware and anything installed with it. Fortect scans Windows for malware and repairs the system files and settings it damaged.

Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free.
Show 8 more facts
Detection namesMicrosoft Defender uses Trojan:Win32/ClickFix.R!ml for commands from ClickFix lures. We found no published Microsoft name for these five exact files; we did not scan them
NameJsDelivr virus
Domain registered16 May 2012
Evidence5 write-ups by security sites; details still limited
First seen12 September 2026
DistributionTypically fake installers, cracked programs, e-mail attachments, fake "verify you are human" pages and ads for popular apps
DamageInstalls other malware, often several programs at once
Facts checked8 October 2026

Facts checked on 8 October 2026 against the URLhaus data for cdn.jsdelivr.net in our job record, RDAP, one plain request from our server (no browser), jsDelivr's documentation, and reports by Microsoft (via The Hacker News and BleepingComputer), Check Point and Darktrace. We did not download the reported files and infected no PC; the removal steps follow Microsoft's pages and were not tried on a live infection.

What jsDelivr is, and why a security tool may call it a virus

jsDelivr is not a virus. It is a free public content delivery network that copies files from npm packages and GitHub repositories and serves them fast from servers around the world. Millions of websites load scripts and fonts from cdn.jsdelivr.net every day. Because anyone can publish a file to GitHub, and jsDelivr will serve that file, criminals sometimes use it as a free and trusted looking place to keep their malware. The service is safe; some of the files it passes along are not.

In September 2026 the abuse.ch project URLhaus listed five such file addresses on cdn.jsdelivr.net. Four were scripts tied to ClickFix tricks, where a fake check on a web page tells you to paste a command, and three of them were tagged ACRStealer, a password stealer for Windows.

The fifth was an installer for Nezha, a server monitoring tool that attackers also use for remote access. All five were offline when we read the data on 8 October 2026.

  1. 1

    What URLhaus lists

    Five file addresses on cdn.jsdelivr.net, all under the /gh/ path, which means each file was copied from a GitHub repository. They were added on 12, 13, 15, 17 and 28 September 2026. Every entry has the threat label malware_download and the status offline. Three were reported by abuse_ch, one by n3x77 and one by drewfink.

  2. 2

    What the tags mean

    ClickFix is a trick where a web page asks you to copy and paste a command to fix an error or prove you are human. TerminalFix is a newer form of it that sends you to Windows Terminal or PowerShell. ACRStealer is a stealer sold to criminals. powershell and ps1 say the file is a PowerShell script. redis and sh say the last file is a Linux shell script used against Redis database servers.

  3. 3

    What we could not confirm

    We did not download the files, so we cannot show what is inside them. URLhaus tags are reports, not a full analysis. We also do not know which web pages showed the lures or how many people pasted the commands.

  4. 4

    What this means for you

    If your browser, antivirus or firewall only named cdn.jsdelivr.net, nothing is proven: almost every visit to that address is a normal website loading a normal script. The risk is for a person who pasted a command from a web page into the Run box, Terminal or PowerShell, and for the owner of a Linux server that ran an installer it should not have.

Kind of threat
Malware delivered through a legitimate CDN: ClickFix scripts tagged ACRStealer, one TerminalFix file and one Nezha agent installer
The service
jsDelivr, a free open source CDN for npm and GitHub files. The domain jsdelivr.net was registered on 16 May 2012 through Amazon Registrar, Inc. (RDAP, read 8 October 2026)
Where the files were
hxxps://cdn.jsdelivr[.]net/gh/<GitHub account>/<repository>@<version>/<file>, five different GitHub accounts
URLhaus entries
5 file addresses, added between 12 and 28 September 2026; all 5 offline on 8 October 2026
Delivery trick
ClickFix and TerminalFix: a page tells you to paste a command; the command fetches the script from jsDelivr
Platform
Windows for the ClickFix and ACR Stealer files. Linux servers for the Nezha installer. Nothing we read says iPhone or Android

What jsDelivr virus (malware served through cdn.jsdelivr.net) does on an infected PC

What we checked on 8 October 2026, and what we could not

We sent one plain request from our server to https://cdn.jsdelivr.net/ on 8 October 2026, with no browser and no clicks. It answered with a redirect (HTTP 301) to https://www.jsdelivr.com, the project's home page, through Cloudflare. That is what a healthy CDN does with its bare address. It does not test the five reported files, and a quiet answer clears nothing.

Our check, 8 October 2026

  • The service answers normallyHTTP 301 to https://www.jsdelivr.com, served by Cloudflare. No page title, no notification request.
  • Domain registrationjsdelivr.net, registered 16 May 2012, registrar Amazon Registrar, Inc., status client transfer prohibited. A long lived registration is what a real service looks like.
  • URLhaus listingFive file addresses under /gh/, tagged ACRStealer, ClickFix, TerminalFix, powershell, ps1, redis and sh; added 12 to 28 September 2026.
  • Are the files still served?All five are marked offline by URLhaus. That usually means the GitHub repository or file is gone or the file was blocked.
  • What we did not doWe did not request or download the reported files and did not run them. Other files of the same kind may appear under new GitHub accounts at any time.

Safe service, abused by some uploaders cdn.jsdelivr.net itself is a legitimate and widely used CDN. The danger is in specific files that criminals publish on GitHub and then link through jsDelivr. Judge the full link, not the domain, and never run a command a web page asks you to paste.

The five reports, in order

The reports cover just over two weeks. Dates and tags come from the URLhaus data in our job record; the times are UTC.

  1. 16 May 2012

    jsdelivr.net is registered

    RDAP shows the domain registered on 16 May 2012 through Amazon Registrar, Inc. The service has run for over fourteen years.

  2. 12 September 2026

    First ACR Stealer script

    At about 07:25 UTC abuse_ch adds a file under a GitHub account whose name is a string of digits and hyphens. Tags: ACRStealer, ascii, ClickFix, powershell, ps1.

  3. 13 September 2026

    A second one, same pattern

    At about 12:57 UTC another file is added from a different account with a name made of hex like groups. Same five tags.

  4. 15 September 2026

    A third one

    At about 07:01 UTC a third file is added, from an account named with digits only. Tags: ACRStealer, ascii, powershell, ps1.

  5. 17 September 2026

    A file named llm, tagged TerminalFix

    At about 15:44 UTC n3x77 reports a file called llm in a repository named futures-import, pinned to commit 04e2419. Tags: ClickFix and TerminalFix.

    Timeline of five URLhaus reports for cdn.jsdelivr.net between 12 and 28 September 2026 with their tags
    The five URLhaus reports for cdn.jsdelivr.net, September 2026. Each file came from a different GitHub account.
  6. 28 September 2026

    A Nezha agent installer

    At about 06:11 UTC drewfink reports agent/install.sh from a repository called scripts under the account nezhahq, on the main branch. Tags: redis and sh.

  7. 8 October 2026

    All offline, and our check

    All five entries are marked offline. Our plain request to the CDN's bare address gets a normal redirect to the project home page.

Our reading of the pattern: the three ACR Stealer files come from throwaway looking accounts with random names, which fits a campaign that makes new GitHub accounts as old ones are removed. That is an inference from the names, not something a report states.

How criminals use jsDelivr, and why it works for them

jsDelivr does not check what a GitHub file does before it serves it, in the same way a post office does not open every letter. That is by design: the service exists to deliver open source code fast. Criminals take advantage of the trust that security tools and people give to a well known address.

Four steps: a lure page tells you to paste a command, you paste it into Run or Terminal, the command fetches a file from cdn.jsdelivr.net, and the stealer runs
The ClickFix chain as vendors describe it. jsDelivr only carries the file; the step that does the harm is the pasted command.
  1. 1

    Any GitHub file gets a jsDelivr address

    jsDelivr's own documentation gives the pattern /gh/user/repo@version/file, where the version can be a release, a commit or a branch. Anyone who puts a file in a public GitHub repository can therefore link to it through cdn.jsdelivr.net, with no sign up at jsDelivr.

  2. 2

    The address looks trusted

    Check Point wrote on 20 July 2023 that attackers can use the CDN to avoid security tools that treat web downloads as suspicious, because many legitimate packages are loaded from jsDelivr. A firewall cannot block the whole domain without breaking a large part of the web.

  3. 3

    Files can outlive their source

    In the same report Check Point found files from an npm package that npm had marked malicious about a month earlier still reachable through jsDelivr, and another case more than a year old. Pinning a link to a fixed commit, like the @04e2419 in one of our entries, keeps a file reachable as long as that copy exists.

  4. 4

    The CDN removes content for security reasons

    jsDelivr's documentation says content may be restricted for serious security or legal reasons backed by clear evidence, and asks for such reports to go privately to legal@jsdelivr.com with the affected URLs. It does not remove files only because they were deleted upstream.

What ACR Stealer is

Three of the five files were tagged ACRStealer. Microsoft's Defender Experts reported a surge of ACR Stealer attacks on business customers from late April to mid June 2026, in a post of 16 July 2026.

QuestionWhat the sources saySource
What is it?A stealer sold to criminals as a service; BleepingComputer says it is believed to be a rebrand of Amatera StealerBleepingComputer, 18 July 2026
How does it arrive?ClickFix: a pasted command starts mshta.exe or rundll32.exe, then obfuscated PowerShell, sometimes a bundled Python loaderThe Hacker News, 17 July 2026; BleepingComputer
Where do the lures come from?Likely malicious ads or poisoned search results, and fake pages that copy real software brandsThe Hacker News
How does it hide?Code hidden in the pixels of a JPEG, runs in memory, copies timestamps from notepad.exe, clears PowerShell historyThe Hacker News
How does it stay?A hidden scheduled task that poses as a software updateThe Hacker News; BleepingComputer
Which system?Windows. Every chain described uses Windows programsMicrosoft via both articles

The TerminalFix file and the Nezha installer

Two of the five reports are not ACR Stealer. They show two other ways the same CDN shows up in attacks.

  1. 1

    TerminalFix: the command goes into Windows Terminal

    Microsoft described TerminalFix on 28 August 2026, as reported by BleepingComputer on 31 August. Fake Cloudflare checks on hacked websites copy a PowerShell command and tell the visitor to run it in Windows Terminal. The chain Microsoft described hides code in PNG pictures, sets a scheduled task and a Run key, and opens a tunnel into the victim's network. We do not know what the file named llm on jsDelivr did.

  2. 2

    Nezha: a real tool used as a back door

    Nezha is an open source monitoring tool for servers with a remote shell. Darktrace wrote on 10 June 2026 that attackers install a modified Nezha installer as root on Linux servers to keep remote access, and found 141 infected servers on one attacker panel. Huntress, as reported, saw the same tool used on Windows to add Defender exclusions.

  3. 3

    Why a real project's installer can be reported

    The reported path, nezhahq/scripts@main/agent/install.sh, has the Nezha project's own name. Our reading: the file may be the genuine installer, and the report concerns how attackers used it against exposed Redis servers (the redis tag), not the file being changed. URLhaus does not say which.

What jsDelivr virus (malware served through cdn.jsdelivr.net) can steal or download

What a stealer from these chains can take

The list below is what the sources say ACR Stealer takes. It applies only to a Windows PC where a pasted command really ran.

Reported as taken

  • Saved browser passwords
  • Cookies and session tokens
  • Chrome and Edge data decrypted with DPAPI
  • PDF files on the Desktop and in Downloads
  • Microsoft 365 documents
  • Files in synced OneDrive and SharePoint folders
  • Crypto wallet data
DataDetailSource
Browser loginsLogin Data and Web Data databases of Chrome and Edge, decrypted with DPAPIThe Hacker News; BleepingComputer
SessionsCookies and tokens that let a thief open your accounts without your passwordMicrosoft via BleepingComputer
DocumentsPDFs, Office documents, OneDrive and SharePoint files, packed into an archive before sendingBleepingComputer
WalletsCrypto wallet information is named in vendor overviews of the familyVendor overviews

What this can cost you

Seeing cdn.jsdelivr.net in a log costs nothing. The risks below are for a PC where a pasted command ran, or a server where an installer ran that nobody chose.

  • High

    Accounts opened without a password

    Stolen session tokens can keep working after you change the password. Microsoft's advice is to revoke sessions and tokens, not only to reset passwords.

  • High

    Work files and cloud folders

    OneDrive and SharePoint files synced to the PC can be copied, so a home infection can become an employer's data leak.

  • High

    A network opened from inside

    In the TerminalFix chain the goal was a tunnel into the internal network, which Microsoft says can lead to stolen credentials or ransomware.

  • Medium

    A server used by someone else

    A Nezha agent installed by an attacker gives remote command access to a Linux server.

  • Low

    Nothing, if you only saw the name

    A blocked request or a log line with cdn.jsdelivr.net is not an infection. Most such requests are normal websites.

How to check the PC for jsDelivr virus (malware served through cdn.jsdelivr.net)

How to tell a bad jsDelivr link from a normal one

Look at what is after the domain and at how the link reached you. The domain alone tells you nothing either way.

SignNormal useAbuse in the reports
How you met itA script tag inside a website's own codeA command a web page asked you to copy and paste
The path/npm/ or /gh/ with a known project name such as a library or font/gh/ with random digits or hex groups as the account and repository
The fileA .js, .css or font file with a clear nameA file with no ending, a .ps1 script or an .sh installer
Who opens itYour browser, quietly, while showing a pagepowershell.exe, mshta.exe, Windows Terminal or bash, started by you
What it asks of youNothingPress Windows key and R, paste, press Enter, to fix an error or pass a check

The single rule that covers all four ClickFix files: no real website, CAPTCHA or error message needs you to paste a command into Windows. Microsoft's ClickFix analysis of 21 August 2025 says the trick relies on people not knowing what the Run dialog is for.

Check your PC before you delete anything

The question that matters: did you paste and run a command that a web page gave you? If not, and you only saw the address in a log, you can stop here. If yes, or you are not sure, do these checks. None of them deletes anything.

Use another device for banking, email and work until you finish.

  1. 1

    Disconnect first

    Turn off Wi-Fi or unplug the cable. A stealer needs the connection to send what it takes.

  2. 2

    Look at Protection history

    Open Windows Security > Virus & threat protection > Protection history. Write down any detection from the day you ran the command.

  3. 3

    Look at the Run box history

    Commands typed in the Run box are remembered. Press Windows key and R and open the drop down list. A long line with powershell, mshta or a jsdelivr address is the trace of the lure.

  4. 4

    Open Task Scheduler

    Press Start, type Task Scheduler, open Task Scheduler Library and look for a task with an update like name that runs PowerShell, Python or a script from a user folder. Microsoft says ACR Stealer hides as such a task. Note it; do not delete yet.

  5. 5

    Check Startup apps and odd processes

    Open Settings > Apps > Startup and Task Manager. A pythonw.exe, mshta.exe or a hidden PowerShell running with no reason is worth a note.

How to remove jsDelivr virus (malware served through cdn.jsdelivr.net)

How to remove jsDelivr virus

A loader's job is to install other malware, so treat the PC as infected with more than one program until the scans are clean.

  1. Step 1: Delete scheduled tasks that bring it back

    Programs like jsDelivr virus add a scheduled task so they return after an uninstall or reopen a page at every sign-in. Start Task Scheduler, open Task Scheduler Library and sort by Last Run Time to see what ran recently.

    On the Actions tab, a program in a user folder, a script or a web address is a warning sign; right-click such a task and choose Delete.

    Tasks with names copying Google, Edge or Windows updaters but pointing to an odd folder are typical. The tool looks the same in Windows 11 and Windows 10.

    Task Scheduler Library with a task selected and its Actions tab showing the program it starts
    Windows 11: Task Scheduler Library, the task selected, the Actions tab shows the file it runs.

    Full procedure with screenshots: Remove what malware leaves behind in Windows

  2. Step 2: Remove it from startup

    Press Ctrl + Shift + Esc to open Task Manager and select Startup apps (Windows 11) or the Startup tab (Windows 10). Disable entries you do not recognise, especially ones with no publisher or with a name that copies a Windows component.

    Right-click an entry and choose Open file location to see where it runs from: programs in %AppData% or %Temp% deserve a closer look. Some entries are not listed there but in the registry Run keys, which the procedure below shows how to check.

    Full procedure with screenshots: Stop apps from opening at startup On uGetFix

  3. Step 3: Delete the folders left behind

    Uninstalling often leaves the program's folders, and some threats reinstall themselves from them.

    Press Windows + R, type %LocalAppData% and press Enter, then do the same for %AppData% and %ProgramData%, and look for folders named after jsDelivr virus, its publisher or created on the day the problem started.

    Delete those folders, and check C:\Program Files and C:\Program Files (x86) too.

    If Windows says a file is in use, end it in Task Manager or delete the folder after a restart in Safe Mode. The folders are the same in Windows 11 and Windows 10.

    Full procedure with screenshots: Remove what malware leaves behind in Windows

  4. Step 4: Scan the PC, then run the offline scan

    A scan finds the parts of jsDelivr virus that the manual steps cannot see. In Windows Security > Virus & threat protection > Scan options, start a Full scan and quarantine what it reports.

    Follow it with Microsoft Defender Antivirus (offline scan) > Scan now, which restarts the PC and checks the disk while Windows and the malware are not running.

    It takes about 15 minutes and works the same in Windows 11 and Windows 10. If either scan finds something, run the full scan again after removal until it comes back clean.

    Windows Security Scan options with Microsoft Defender Antivirus offline scan selected
    Windows 11: Windows Security > Virus & threat protection > Scan options.

    Full procedure with screenshots: Run a Microsoft Defender Offline scan

  5. Step 5: Change passwords from another device and sign out other sessions

    JsDelivr virus can copy saved passwords, cookies and session tokens and send them out in seconds, so cleaning the PC does not undo the theft.

    Change your passwords on a device that was never infected, starting with the e-mail account, since every other reset goes through it. On each account, end all other sessions and check the recovery e-mail, phone number and forwarding rules.

    Then turn on two-step verification. Sign in on the Windows 11 or Windows 10 PC again only after the offline scan is clean.

    Full procedure with screenshots: Turn on two-step verification / secure a hacked account

If you run a Linux server and the Nezha report concerns you

The Nezha entry was tagged redis and sh. That points to servers, not home PCs. The Windows steps on this page do not apply to a Linux server.

  1. 1

    Look for an agent you did not install

    Check running services and processes for a Nezha agent, and check cron for jobs that pipe a downloaded script into a shell. Darktrace's case used a cron job named ngk.

  2. 2

    Close the door it came through

    A Redis server must not be reachable from the internet without a password. Restrict it to localhost or a private network.

  3. 3

    Rebuild if root ran it

    A script that ran as root can change anything. Rebuild the server from a known good image and rotate every key and password stored on it.

If you use a Mac, an iPhone or an Android phone

The four ClickFix reports and the sources describe Windows. jsDelivr is just as reachable from any device, but nothing we read says these files run on a phone or a Mac.

Your deviceWhat we knowWhat to do
MacMicrosoft notes that ClickFix lures also exist for macOS with other stealers, but none of these five files is tagged for MacIf a page asked you to paste a command into Terminal, treat the Mac as exposed and change passwords from another device
iPhone or iPadNo source describes these files on iOSNothing to remove. Change passwords you typed into a strange page
AndroidNo source mentions these files on AndroidNothing to remove for this threat

After removal: passwords, accounts and prevention

Secure your accounts after the clean-up

Assume that whatever was saved in the browsers on this PC while the PC showed A command pasted from a web page that fetched a file from cdn.jsdelivr.net in the list of installed apps has been copied:

  • passwords
  • cookies
  • autofill data

Work from a clean device, or from this PC once the offline scan finds nothing.

Start with your main e-mail account, because it can reset everything else, then banking and payment, then social and gaming accounts. Change each password, sign out of all sessions and turn on two-step verification: Turn on two-step verification / secure a hacked account.

The full order, including crypto wallets and card replacement, is in securing your accounts after malware.

After a clean PC: protect what was taken

Cleaning the PC does not undo what was already sent. Do the account steps from another device first.

Five steps in order: disconnect the PC, change passwords from another device and sign out all sessions, run Defender Offline, remove startup items, reset Windows if unsure
The order of actions after running a ClickFix command. Steps follow Microsoft's pages; we did not test them on an infected PC.
  1. 1

    Change passwords from a clean device

    Start with email, then bank, work, cloud storage and crypto. Anything saved in the browser on that PC should be treated as known.

  2. 2

    Sign out every session

    Use each account's option to sign out of all devices. This kills stolen cookies and tokens, which a new password alone may not.

  3. 3

    Tell your employer

    If the PC had work accounts or synced OneDrive or SharePoint folders, tell IT the same day. Microsoft's advice is to isolate the host, rotate credentials and revoke tokens.

  4. 4

    Move crypto

    If a wallet was on the PC, make a new wallet on a clean device and move the funds.

Keep yourself out of this kind of chain

The CDN is the middle of the chain. Every report starts with a person pasting a command.

Do

  • Close any page that tells you to press Windows key and R, open Terminal or paste a command.
  • Keep Windows, your browser and Microsoft Defender updated.
  • Use a password manager and two step sign in.
  • Report a bad file to legal@jsdelivr.com with the full link, and to GitHub for the repository.
  • Server owners: keep Redis and other admin services off the open internet.

Don't

  • Do not block the whole of cdn.jsdelivr.net: many sites will break.
  • Do not trust a link just because the domain is famous.
  • Do not change passwords on the PC you suspect.
  • Do not treat a clean quick scan as proof after you ran a pasted command.

Questions about jsDelivr virus (malware served through cdn.jsdelivr.net)

Is jsDelivr a virus?

No. jsDelivr is a free, open source content delivery network that serves files from npm and GitHub for millions of websites. Its domain has been registered since 2012.

It is reported only because some people publish malicious files on GitHub and link to them through it. The service is safe; specific files can be dangerous.

Why did my antivirus block cdn.jsdelivr.net?

Most likely it blocked one file address, not the service. Look at the full link in the alert.

If it is a script your browser loaded for a normal website, the block may be a false alarm on that file. If the block came after you pasted a command from a web page, treat it as an attack.

What files were reported on jsDelivr?

URLhaus lists five, added between 12 and 28 September 2026:

  • three PowerShell scripts tagged ACRStealer and ClickFix
  • one file named llm tagged ClickFix and TerminalFix
  • one Nezha agent installer tagged redis and sh

All five were offline on 8 October 2026. Each file came from a different GitHub account, and none was made by jsDelivr itself.

Is cdn.jsdelivr.net safe to visit?

Yes, as a service. Our request on 8 October 2026 got a normal redirect to the project home page. What matters is the specific file and how you came to open it.

A command that a web page asks you to paste is never safe, whatever address it contains. Most visits happen without you noticing, when a site loads its scripts.

I pasted a command from a CAPTCHA page. What now?

Disconnect the PC, change your passwords from another device and sign out all sessions, then run a Microsoft Defender Offline scan and look for odd scheduled tasks.

If you are unsure, reset Windows. The ACR Stealer chains reported in 2026 take browser passwords, cookies and documents. Tell your employer if work accounts were on the PC.

What is ACR Stealer?

A stealer sold as a service to criminals and believed to be a rebrand of Amatera Stealer. Microsoft reported a surge from late April to mid June 2026.

It arrives through ClickFix commands and takes browser passwords, cookies, tokens and documents from Windows PCs. Microsoft's advice is to revoke sessions and tokens, not only to change passwords.

Can I block jsDelivr to be safe?

Blocking the whole domain will break many websites that load their scripts from it. A better step is to never run pasted commands and, in a company, to block mshta.exe and limit PowerShell for normal users, as Microsoft advises. At home, the safest habit is simple: close any page that asks you to open the Run box or Terminal.

How do I report a malicious jsDelivr file?

jsDelivr's documentation asks for serious security reports to go privately to legal@jsdelivr.com with the affected links and evidence. Report the GitHub repository to GitHub as well, because jsDelivr copies the file from there. You can also report the full link to URLhaus at abuse.ch, which shares it with security vendors and network operators who block such files.

Does this affect my iPhone or Android phone?

Nothing we read says these files run on phones. They are Windows scripts and one Linux installer. If you typed a password into a strange page on your phone, change it.

The tricks in these reports ask you to press keys that exist only on a Windows keyboard, so a phone cannot follow them. A Mac can be targeted by other ClickFix lures through Terminal.

Will Fortect remove jsDelivr virus?

Fortect scans Windows for malware and unwanted programs and repairs the system files and settings they change, and its free scan shows what it finds on your PC before you decide anything.

For jsDelivr virus, follow the plan above as well: the browser steps take back permissions and settings that no scanner treats as a threat, and uninstalling the program that brought it removes the source.

Run Microsoft Defender's full scan and, if anything was found, its offline scan as a second opinion. If the symptoms are gone after the plan and both scans are clean, there is nothing more to do.

Sources

More removal guides

Remove porterneuman.mx: PowerShell and JavaScript files tied to the AveMaria remote access trojan, and what to do

porterneuman.mx is a web address where URLhaus found five script files in a WordPress plugin folder on 30 September 2026: four PowerShell stubs and one JavaScript file. One stub is tagged AveMariaRAT, a remote access...TrojansHigh riskUgnius Kiguolis ·

Remove Memz virus

Memz virus is the custom-made trojan that overwrites Windows boot sequence with Nyan Cat meme animation Memz virus is the trojan originally created by Leurak as viewer-made malware forTrojansHigh riskLucia Danes ·

Remove qpwot.cfd: a server handing out scripts that lead to the MassLogger and VIP Keylogger stealers, and what to do if one ran

qpwot.cfd is a web address that URLhaus listed seven times on 6 October 2026 for JavaScript files and PowerShell files named secured_stub.ps1, tagged MassLogger and VIPKeylogger, two keyloggers that steal passwords...TrojansHigh riskUgnius Kiguolis ·

Remove www.beinke-aufzuege.de: a hacked website hosting FormBook PowerShell stubs, and what to do if a script fetched them

www.beinke-aufzuege.de is the address of a German website that URLhaus lists for four PowerShell files tagged Formbook, a password stealer for Windows, hidden in random folders inside the site's own Joomla media...TrojansHigh riskUgnius Kiguolis ·

Questions and experiences: jsDelivr virus (malware served through cdn.jsdelivr.net)

Still seeing it, or found something we did not cover? Ask here: members and our editors answer. Reading is open; writing needs a free account.

0 comments

…

5,441 members already hereReading, writing, commenting and voting. 0 verified · 166 joined this year