logo

New macOS stealer campaign uses Script Editor in ClickFix attack

ID: 225bbd16-b5a8-5d44-b097-24b93ed0e74d

STIX ID: report--225bbd16-b5a8-5d44-b097-24b93ed0e74d

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2026-04-08

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

A campaign observed by security researchers uses malicious Apple-themed web pages and the applescript:// URL scheme to launch macOS Script Editor with prefilled code that runs an obfuscated 'curl | zsh' command, downloading and executing a Mach-O payload identified as Atomic Stealer (AMOS). The infostealer targets Keychain, browser cryptocurrency wallets, passwords, cookies and can include a backdoor for persistence; users are advised not to run Script Editor prompts from untrusted sources and to rely on official Apple guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.