DeepSeek did full reverse engineering on this.
DeepSeek did full reverse engineering on this.
I was lucky enough to stop at the password prompt (something felt off). Gemini had pretty much established that it was almost entirely certain nothing left my Mac as I didn't enter my password and I hadn't. It also found some evidence that had I entered my password those evidences would have been gone certainly from my mac and then I had the script beautified and de-obfuscated and read it myself and had a much needed sigh of relief. The script literally did nothing unless it had the password.
I started using nextdns after that but then the site I tricked on was a legit but very small e-com site from my country which was hacked/taken over, so not sure how nextdns can even be helpful here. Also the script was identified as malicious by only one antivirus that I had tried later, just to see. I had tried 8–9 of them. Later I uninstalled all of them and even stopped using NextDNS.
I wish browsers like Safari allowed specific options like disabling clipboard interaction instead of the "disable js" as the only possible option.
Later (and still) I feel a bit of shame that how could I fall for this as a somewhat proud cynic and as well versed in "browsing the Interwebs" as it normally gets :) That (as small as it was) experience gave a whole new meaning to malicious online attacks for me and a whole lot of empathy towards people who fall for such attacks. It was my first "experience". It might sound weird but the feeling of violation still lingers.
(just wanted to share this)