The Script Editor Shift: How ClickFix Evades macOS 26.4 Security to Deliver Atomic Stealer
ID: dffbef09-f779-5f61-bc42-a6138b21cacf
STIX ID: report--dffbef09-f779-5f61-bc42-a6138b21cacf
Feed Name: securityonline.info
Threat Score
Jamf Threat Labs reports a ClickFix adaptation where attackers use the applescript:// URL scheme to open Script Editor with an obfuscated first-stage AppleScript that downloads a Mach-O second-stage binary (Atomic Stealer) to /tmp, removes extended attributes, sets execution permissions, and runs it — bypassing macOS Terminal paste-scanning protections and enabling information-stealing on infected Macs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
