logo

Fake BlueWallet steals passwords, accounts, and crypto from Macs

ID: eb7b029d-8192-58a8-87d5-ce87abc0321e

STIX ID: report--eb7b029d-8192-58a8-87d5-ce87abc0321e

Feed Name: Malwarebytes Blog

Threat Score
75/100

Date Published: 2026-06-01

Date Updated: 2026-06-03

...
...

A malicious campaign impersonating BlueWallet hosts a fake download page that coerces Mac users to open an AppleScript which downloads a hidden shell payload (.sysupd.sh). The payload creates a hidden working directory, weakly obfuscates configuration, harvests browser data, desktop and extension wallets, password manager and 2FA artifacts, SSH/AWS/GPG files, and notes, establishes persistence via a LaunchAgent, continuously hijacks clipboard crypto addresses (BTC/ETH/SOL) to replace them with attacker-controlled addresses, and exfiltrates data and accepts commands over a Telegram bot channel; indicators include a SHA-256 for the AppleScript, two hostile domains, and three cryptocurrency addresses used for clipboard substitution.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.