logo

MacSync macOS Infostealer Leverage ClickFix-style Attack to Trick Users Pasting a Single Terminal Command

ID: b45bcf6d-49b8-510e-b6da-3ee1437368bf

STIX ID: report--b45bcf6d-49b8-510e-b6da-3ee1437368bf

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-01-23

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

MacSync is a script-driven macOS infostealer (offered as Malware-as-a-Service) that uses deceptive landing pages and a one-line Terminal command to bypass Gatekeeper and deploy a Zsh loader and AppleScript payload; it harvests cryptocurrency-related data (browser wallet extensions, desktop wallets, seed phrases, private keys), SSH keys, Keychain entries and credentials, and can trojanize hardware wallet apps to capture PINs and recovery phrases, with multiple rotating C2 domains indicating an active, scalable campaign.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.