logo

macOS Users Hit by Python Infostealers Posing as AI Installers

ID: cfbff0fd-24cf-5227-a3b3-696d92ac58c7

STIX ID: report--cfbff0fd-24cf-5227-a3b3-696d92ac58c7

Feed Name: HackRead

Threat Score
70/100

Date Published: 2026-02-05

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

Microsoft Defender research identified three major macOS infostealer campaigns—DigitStealer, MacSync, and Atomic Stealer—delivered via fake ads, malicious installers, and social-engineered Terminal commands. These campaigns aim to exfiltrate cryptocurrency wallets, browser-saved passwords, and developer credentials, then remove traces to impede detection; analysts warn the attacks exploit user trust and native macOS tools, posing significant risk to individuals and organizations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.