A legitimate CAPTCHA may ask you to select images, tick a box or complete a browser challenge. It does not need you to open PowerShell, Terminal or the Windows Run dialog and paste a command. That instruction is the scam.
Why the trick works
The page copies a hidden command to the clipboard, then presents keyboard steps as “verification.” Pasting and running it gives the command the user's own permission, allowing malware or an infostealer to download.
Stop at these instructions
- Press Windows+R, Win+X or open Terminal.
- Paste from the clipboard without showing the command.
- Disable security software to finish verification.
- Install a browser update from an unfamiliar page.
If you already ran the command
Disconnect the device from the network, contact workplace IT if applicable and use a clean device to protect email and financial accounts. End active sessions, not only passwords, because infostealers target browser cookies. Preserve the URL and command for incident response.
Closing the page before executing anything is enough. A website can verify browser behavior inside the page; it should never ask for operating-system commands as proof that you are human.
Why antivirus may not stop the first step
The user is executing the command through a trusted operating-system tool, so the initial action may resemble legitimate administration. Later downloads may be detected, but prevention is stronger: browsers do not need shell access to confirm a human visitor.
For workplace teams
Block known campaign domains, restrict script interpreters where operationally possible and teach staff one memorable rule: a CAPTCHA stays inside the webpage. Preserve the copied command for analysis rather than running it in a test production device.
Understand the clipboard trick
The page may silently place a command on the clipboard and then tell the visitor to press a keyboard sequence. The command can download a second program, steal browser data or establish persistence. The visible “verification code” may not match what is actually pasted.
Containment after execution
Disconnect the affected device, note the time and exact page, and contact a qualified responder. From another trusted device, protect email, password-manager and financial accounts, revoke sessions and review security alerts. Simply deleting browser history does not undo a command that ran through the operating system.
Organizations can reduce exposure with application control, restricted scripting, browser protections and training that uses one clear rule: a website never needs a person to paste an operating-system command to prove they are human.
Sources and further reading
Use the right privacy tool for the task
A browser proxy changes the network path for one session. Review the Privacy Policy and use a trusted direct connection for sensitive accounts.