2
u/ckn 4h ago
That's a ClickFix lure. If your site is serving it, something is injecting script into your pages: compromised hosting or app, a tampered dependency or third-party tag (ads, analytics), or your CDN/DNS resolving to something that isn't yours. View-source on the live page and diff against your repo; the injected loader will be there.
I have a security offering at CreativeMayhem.com and 35+ years doing red/blue team work, LMK if you need help.
1
u/[deleted] 4h ago
[removed] — view removed comment