logo

Infiniti Stealer: a new macOS infostealer using ClickFix and Python/Nuitka

ID: 277c4562-50d5-5498-8d35-79dd55c85f86

STIX ID: report--277c4562-50d5-5498-8d35-79dd55c85f86

Feed Name: Malwarebytes Blog

Threat Score
72/100

Date Published: 2026-03-26

Date Updated: 2026-04-28

...
...

A newly documented macOS infostealer named Infiniti Stealer (initially tracked as NukeChain) uses a ClickFix fake CAPTCHA page to trick users into running a bash installer; the multi-stage attack drops a Nuitka-compiled Python stealer that collects browser credentials, Keychain entries, crypto wallets, developer secrets and screenshots, exfiltrating data via HTTP and notifying operators over Telegram. The report includes stage-by-stage analysis, IOCs (hashes, C2 domains/URLs, temp paths, packer magic), sandbox-evasion checks, and recommended remediation steps.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.