logo

Reaper macOS Infostealer Abuses Script Editor to Steal Crypto and Passwords

ID: 9f570944-4fae-524a-851f-6a2bba31aa76

STIX ID: report--9f570944-4fae-524a-851f-6a2bba31aa76

Feed Name: HackRead

Threat Score
78/100

Date Published: 2026-06-05

Date Updated: 2026-06-05

Author: Deeba Ahmed

...
...

Researchers identified a macOS malware campaign distributing a Reaper (SHub Stealer) variant via typo-squatted and fake app download pages that abuse applescript:// links to auto-run malicious code in Script Editor, bypassing Terminal protections; the malware steals documents and browser/crypto credentials, chunks and uploads compressed archives to a C2, modifies desktop wallet applications to intercept funds, and persists via a fake Google Software Update directory.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.