Slickdeals is community-supported.  We may get paid by brands for deals, including promoted items.
Forum Thread

Anyone else get a Malicious Ad / Link Hijack today?

330 129 August 4, 2026 at 06:02 PM
I was just browsing the "Sonic Drive-In, rewards members BOGO burger 1x/week through August 30th" deal, clicked the giant blue "Get Deal at Sonic Drive-In" button, and got redirected to a "codevectornet.co.in" website with a fake CAPTCHA telling me to click "Allow" on a notification setting prompt. Tested on my other browsers (Firefox, Edge) but couldn't replicate it anymore. I'm guessing there's a malvertising ad in rotation that may be hijacking links to dupe users into accepting the notification.

I've never seen this type of attack before, but some quick research came back with "codevectornet.co.in is a domain registered exclusively for malicious intent. It operates purely as a host for scareware, malvertising, and social engineering infrastructure."
About the OP
Joined May 2013 L4: Apprentice
129 Reputation Points
10 Deals Posted
446 Votes Submitted
330 Comments Posted

Your comment cannot be blank.

Sign up for a Slickdeals account to remove this ad.

Joined Jul 2007
Living Ghost
> bubble2 4,987 Posts
5,296 Reputation
Global Mod
SpaceCallahan | Staff
08-05-2026 at 01:36 AM.
08-05-2026 at 01:36 AM.
Quote from spartanvi :
I was just browsing the "Sonic Drive-In, rewards members BOGO burger 1x/week through August 30th" deal, clicked the giant blue "Get Deal at Sonic Drive-In" button, and got redirected to a "codevectornet.co.in" website with a fake CAPTCHA telling me to click "Allow" on a notification setting prompt. Tested on my other browsers (Firefox, Edge) but couldn't replicate it anymore. I'm guessing there's a malvertising ad in rotation that may be hijacking links to dupe users into accepting the notification.

I've never seen this type of attack before, but some quick research came back with "codevectornet.co.in is a domain registered exclusively for malicious intent. It operates purely as a host for scareware, malvertising, and social engineering infrastructure."

Thank you for reporting this. I have passed this information along to our ad team to block them
Reply
Joined May 2013
L4: Apprentice
> bubble2 330 Posts
129 Reputation
Original Poster
spartanvi
08-31-2026 at 11:50 AM.
08-31-2026 at 11:50 AM.
I just noticed it again today, this time for the "Select Subway Sub Club Members: Any Qualifying Footlong Sub" deal. When I click the link I get a redirect to ill-fatedodd.com then cloudzenarc then cyberportalpod.co.in domain to do the same thing I reported in the OP. Click "allow" on a nefarious notification pop-up.

Replicated the same issue on Chrome, Firefox, and Edge (the latter of which I never use). Also tested this by tethering my PC to my phone carrier's 5G network, which replicated the same issue in a clean incognito session.

I've done some troubleshooting to verify whether it's something on my end injecting the malvertising redirect or if it's originating from Slickdeals. With Dev Tools open, I see the ill-fatedodd.com in my network traffic right when I hit the Subway deal's page. When I disable javascript on my brower and refresh the page, the ill-fatedodd.com requests never appear, it's perfectly clean, only traffic from slickdeals domain. To me, this rules out DNS, hosts file manipulation, or client-side network redirect. It's driven by JavaScript. Unfortunately it's becoming too risky to click deal links on this site going forward.
Reply
Last edited by spartanvi August 31, 2026 at 12:22 PM.
Page 1 of 1
Start the Conversation
 
Link Copied

The link has been copied to the clipboard.