logo

New macOS Infinity Stealer uses Nuitka Python payload and ClickFix

ID: 3cf97544-9868-5982-a15a-9b1a818c1612

STIX ID: report--3cf97544-9868-5982-a15a-9b1a818c1612

Feed Name: Security Affairs

Threat Score
70/100

Date Published: 2026-03-30

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

Infinity Stealer is a newly observed macOS infostealer campaign that leverages fake Cloudflare CAPTCHA pages (ClickFix) to coerce victims into pasting Terminal commands. The attack chain uses a Bash dropper, a Nuitka-compiled loader and a Python 3.11 stealer to collect browser credentials, Keychain data, crypto wallets, .env files and screenshots, exfiltrating via HTTP and notifying operators via Telegram; Malwarebytes published the analysis and included IOCs and remediation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.