logo

New Infinity Stealer malware grabs macOS data via ClickFix lures

ID: a5b0d8b9-94e8-5aaa-8ef1-fec658d776fe

STIX ID: report--a5b0d8b9-94e8-5aaa-8ef1-fec658d776fe

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2026-03-28

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Malwarebytes reports a macOS-targeting campaign delivering Infinity Stealer via a ClickFix lure that tricks users into pasting a base64-encoded curl command into Terminal; the payload is a Python infostealer compiled with Nuitka into a native Mach-O binary to evade analysis. The stealer performs anti-analysis checks and harvests browser credentials, Keychain entries, crypto wallets, screenshots and developer secrets, exfiltrating data over HTTP to a C2 and sending notifications to attackers via Telegram.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.