#macOSAttack
The ClickFix campaign targets macOS users with an AppleScript stealer that traps passwords via non-closable dialogs and extracts keychain data, cookies, credentials, and crypto wallets using user-agent filtering. #ClickFix #macOSAttack #AppleScript
macOS ClickFix Campaign: AppleScript Stealers & New Terminal Protections
Netskope Threat Labs details a ClickFix campaign delivering an AppleScript-based macOS infostealer that forces victims to enter their system password via a non-closable dialog and harvests keychain data, browser cookies, saved credentials, extension data, and desktop cryptocurrency wallets. The campaign uses user-agent filtering and paste-into-terminal social engineering to deliver platform-specific payloads and exfiltrates collected data to a hardcoded command-and-control server. #ClickFix #macOS
www.hendryadrian.com
April 21, 2026 at 1:15 AM
New macOS campaign exploits Script Editor via applescript:// links on fake Apple sites, delivering Atomic Stealer to harvest Keychain, wallets, passwords, and cookies through obfuscated ‘curl | zsh’ payloads. #AtomicStealer #macOSAttack #Apple
New macOS stealer campaign uses Script Editor in ClickFix attack
Researchers observed a new campaign delivering the Atomic Stealer to macOS users by abusing the built-in Script Editor via applescript:// links that open pre-filled malicious code. The obfuscated 'curl | zsh' payload decodes and runs a Mach-O Atomic Stealer binary that harvests Keychain items, browser wallet extensions, passwords, cookies, and system data, so users should avoid running Script Editor prompts and follow official Apple guidance. #AtomicStealer #ScriptEditor
www.hendryadrian.com
April 8, 2026 at 11:00 PM
A new macOS attack uses a fake Cloudflare page to trick users into pasting a Terminal command that downloads a Bash script deploying Infiniti Stealer, harvesting sensitive data including browser creds and crypto wallets. #InfinitiStealer #MacOSAttack
Cloudflare-Themed ClickFix Attack Drops Infiniti Stealer on Macs
Malwarebytes reports a macOS-targeted ClickFix campaign that lures victims to paste and run a Cloudflare-themed Terminal command which downloads a Bash script that deploys a Nuitka-compiled loader and the Infiniti Stealer information stealer. The Python-based stealer harvests browser credentials, Keychain items, crypto wallets, developer secrets and screenshots, exfiltrates data to a...
www.hendryadrian.com
March 28, 2026 at 2:00 PM