logo

macOS Malware Hijacks Ledger Live with “Invisible” Electron Archives

ID: 316c18e7-5769-521e-ae20-8f692fbbe3f0

STIX ID: report--316c18e7-5769-521e-ae20-8f692fbbe3f0

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-04-02

Date Updated: 2026-04-23

Author: Ddos

...
...

### Executive Summary Intego Antivirus Labs uncovered a macOS campaign that delivers the OSX/Amos infostealer by replacing an application's Electron ASAR archive with a weaponized version that includes malicious JavaScript. The malicious bundle disables TLS certificate validation globally (NODE_TLS_REJECT_UNAUTHORIZED = '0') to permit silent exfiltration to attacker infrastructure and injects HTML phishing overlays prompting victims to enter 12/24-word recovery phrases, enabling theft of cryptocurrency wallets.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.