Bottom line: India's STPI has been exploited for a TerminalFix-style attack via a fake Cloudflare verification page.
What's happening: A website linked to STPI, which hosts the website of Indian IT services firm, HCL Technologies, has been found to be serving a malicious string via a spoofed Cloudflare verification page. The attack silently copies the string to visitors' clipboards and prompts them to execute it via Windows Terminal.
What to do: Security teams should monitor the website for signs of the attack and block traffic from known IP addresses associated with the attack.