Kash Patel-Linked Apparel Store Goes Dark After Pushing Crypto-Stealing Malware

TL;DR
Based Apparel, linked to FBI Director Kash Patel, went offline after being flagged for distributing 'ClickFix' malware that targeted macOS users to steal crypto. This incident follows a previous data leak involving Patel.
Key points
- Based Apparel linked to FBI Director Kash Patel
- Website pushed ClickFix wallet-draining malware
- Targeted macOS users with deceptive terminal commands
- Flagged as potentially deceptive for MetaMask users
- Second crypto-related incident involving Patel
Mentioned in this story
In brief
- Based Apparel, linked to FBI Director Kash Patel, went dark after being flagged for pushing "ClickFix" wallet-draining malware.
- The infostealer targeted macOS users, tricking them into running terminal commands to steal session tokens and crypto.
- The incident marks the second time Patel has faced crypto-related shenanigans, following a previous data leak.
An apparel store linked to FBI Director Kash Patel appeared to go offline on Friday after onlookers warned that Based Apparel’s website pushed wallet-draining malware.
Until the website apparently went dark, macOS visitors were being prompted to install “ClickFix” malware by copying and pasting a command into their system’s terminal—which put session tokens, browser data, and crypto wallets at risk via an infostealer—a user said on X.
The website was flagged as “potentially deceptive” for MetaMask users, who, when trying to visit the website, received a warning pop-up from the self-custodial wallet that identified “malicious transactions resulting in stolen assets” as among the potential risks.
The attack was reproduced by PCMag; however, Decrypt was unable to do that because Based Apparel plainly says now that “the store will be back online shortly—bolder than ever.”
Infostealer malware is designed to silently and secretly extract sensitive data from users’ devices, with precursors dating back as early as 2006. Two months ago, the FBI said it was investigating several PC games on the Steam platform that installed the malicious software.
It’s unclear whether Based Apparel’s apparent compromise sparked significant losses. The website typically receives an estimated 33,600 visits monthly, according to ahrefs. One of its top pages showcases a camouflage hoodie.
The venture is owned by Patel and Andrew Ollis, who serves on the board of the Kash Foundation as CEO, per The Guardian. Kash Foundation visitors, through one of the nonprofit's primary menus, are directed to Based Apparel.
Although the nonprofit was founded by Patel, he is no longer affiliated in any capacity, according to the organization’s website. A disclosure also makes clear that the Kash Foundation isn’t associated with government agencies, including the FBI.
The FBI director, who has highlighted the bureau’s growing use of artificial intelligence to thwart bad actors, has been the subject of crypto shenanigans before. After Iranian hackers leaked his personal email and burner username, a bevy of Patel-themed meme coins followed.
Q&A
What is ClickFix malware and how does it affect macOS users?
ClickFix is a type of infostealer malware that tricks macOS users into executing terminal commands, allowing it to steal session tokens and crypto wallet information.
Why did Based Apparel's website go dark?
Based Apparel's website went dark after being flagged for pushing wallet-draining malware, prompting warnings from users and security alerts from MetaMask.
What previous incident is linked to Kash Patel regarding crypto?
Kash Patel was previously involved in a data leak incident related to cryptocurrency, marking the second time he has faced issues connected to crypto-related activities.





