logo

The Script Editor Shift: How ClickFix Evades macOS 26.4 Security to Deliver Atomic Stealer

ID: dffbef09-f779-5f61-bc42-a6138b21cacf

STIX ID: report--dffbef09-f779-5f61-bc42-a6138b21cacf

Feed Name: securityonline.info

Threat Score
65/100

Date Published: 2026-04-13

Date Updated: 2026-05-05

Author: Ddos

...
...

Jamf Threat Labs reports a ClickFix adaptation where attackers use the applescript:// URL scheme to open Script Editor with an obfuscated first-stage AppleScript that downloads a Mach-O second-stage binary (Atomic Stealer) to /tmp, removes extended attributes, sets execution permissions, and runs it — bypassing macOS Terminal paste-scanning protections and enabling information-stealing on infected Macs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.