# Malicious Bookmark (Bookmarklet) Phishing Campaign Hijacks Logged-In FOMO Web Platform Accounts

> SlowMist flagged an emerging phishing campaign against users of the FOMO web platform on 2026-10-08. Phishing pages show a fake human-verification (CAPTCHA) step that tricks victims into dragging malicious JavaScript into their browser bookmarks; clicking the bookmark 2-3 times hijacks the already logged-in FOMO account and the crypto assets inside are stolen immediately.

- **Published:** 2026-10-08T00:00:00Z
- **Last reviewed:** 2026-10-08T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-3041
- **ID:** TL-2026-3041
- **Severity:** HIGH
- **Category:** PHISHING
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 6 (full data via the Threadlinqs MCP server — Purple tier)

## Description

On 2026-10-08 SlowMist (via researcher Cos and the @SlowMist_Team account, with a longer Medium analysis titled 'Threat Intelligence Analysis of a Malicious Bookmark Phishing Attack Targeting FOMO Users') warned of bookmark phishing aimed at the FOMO web platform.

Reported attack chain: (1) the victim lands on an attacker-controlled phishing page; (2) the page presents a fake CAPTCHA / human-verification step; (3) the 'verification' instructs the user to drag a snippet of JavaScript into the browser bookmarks bar and save it as a bookmark (a bookmarklet, i.e. a javascript: URI stored as a bookmark); (4) after the user clicks that bookmark 2-3 times while a FOMO web session is open, the script runs in the context of the logged-in FOMO page and the attacker hijacks the account; (5) the attacker immediately steals the crypto assets held in the account. Because the code runs from the user's own bookmark inside the authenticated page, no exploit, malware download or CVE is required and the victim performs the execution step themselves.

SlowMist stated this is not a new technique but a familiar method presented in a new way. The same primitive was documented by SlowMist earlier: its 2022 annual phishing review listed malicious browser bookmarks (JavaScript inserted via phishing pages, fired only when the victim is logged in, used against Discord accounts and project-owner permissions), and in October 2023 a fake-journalist campaign against friend.tech KOLs used a link whose malicious JavaScript was saved by victims and then targeted the account password/2FA and Privy embedded-wallet tokens.

Evidence limits: the primary SlowMist Medium article returned HTTP 403 to automated retrieval, so its full body was not reviewed. None of the secondary outlets (PANews, Coinfomania, KuCoin, ChainCatcher, TokenPost, Phemex) publish phishing domains, script source, exfiltration endpoints, hashes, victim counts or loss totals. Phemex states researchers preserved attacker wallet addresses but did not publish them. No threat actor is named. This incident is distinct from the earlier FomoPeek iOS malware reporting. Detection should therefore focus on behavior (bookmark creation with a javascript: URL, fake-CAPTCHA drag-to-bookmark lure pages, anomalous FOMO session actions) until SlowMist's IOCs are available.

## MITRE ATT&CK

- T1566 Phishing
- T1204.001 Malicious Link
- T1059.007 JavaScript
- T1185 Browser Session Hijacking
- T1657 Financial Theft

## Sources

- [SlowMist: Threat Intelligence Analysis of a Malicious Bookmark Phishing Attack Targeting FOMO Users (primary; not retrievable, HTTP 403)](https://slowmist.medium.com/threat-intelligence-analysis-of-a-malicious-bookmark-phishing-attack-targeting-fomo-users-0985bff1ed36)
- [SlowMist's Cos: Beware of bookmark phishing attacks targeting the FOMO web platform (PANews)](https://panews.io/articles/01a11910-3eac-71d4-9f8d-2db938cf8f3e)
- [Beware of Bookmark-Based Phishing Attacks on FOMO Users (Coinfomania)](https://coinfomania.com/beware-of-bookmark-based-phishing-attacks-on-fomo-users/)
- [SlowMist TI Alert (SlowMist_Team on X)](https://x.com/SlowMist_Team/status/2108039792219013578)
- [Cos (evilcos) original post on X](https://x.com/evilcos/status/2108000520493490578)
- [SlowMist Warns of Bookmark Phishing Attacks Targeting the FOMO Web Platform (KuCoin)](https://www.kucoin.com/news/flash/slowmist-warns-of-bookmark-phishing-attacks-targeting-fomo-web-platform)
- [SlowMist TI Alert on FOMO bookmark phishing (KuCoin insight)](https://www.kucoin.com/fil/news/insight/FOMO/6ac7674938a264000793270e)
- [Slow Mist Yuxian: FOMO web version suffered bookmark phishing (ChainCatcher)](https://www.chaincatcher.com/en/article/2294792)
- [FOMO Web Users Face Bookmark Phishing Attack That Steals Crypto (TokenPost)](https://www.tokenpost.com/news/technology/27682)
- [FOMO Bookmark Phishing Attack Drains Crypto via Malicious JavaScript (Phemex)](https://phemex.com/news/article/bookmark-phishing-attack-targets-fomo-web-users-to-steal-crypto-assets-99115)
- [SlowMist: Analysis of Web3 Phishing Techniques (malicious bookmark precedent)](https://slowmist.medium.com/slowmist-analysis-of-web3-phishing-techniques-ceb1a41d1bd5)
- [SlowMist: Beware of phishing attacks by fake journalists (friend.tech JavaScript bookmark precedent)](https://slowmist.medium.com/beware-of-phishing-attacks-by-fake-journalists-9cc3ed09d7c9)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-3041
