macOS ClickFix Campaign: AppleScript Stealers & New Terminal Protections
Essential information
- Published
- 21/04/2026 02:05
- Modified
- 21/04/2026 09:28
- Tags
- 2026-04-21 applescript browser data exfiltration clickfix credential harvesting cryptocurrency wallet theft infostealer macos session hijacking social engineering
- Related entities
- 6 observables, 20 techniques (mitre), 3 others
Description
A sophisticated ClickFix campaign targets both Windows and macOS users through fake CAPTCHA pages that trick victims into executing malicious commands. The macOS variant deploys an AppleScript-based infostealer that harvests sensitive data including keychain databases, credentials, and session cookies from 12 browsers, over 200 browser extensions, and 16 cryptocurrency wallets. The malware employs a persistent, non-closable dialog box mimicking legitimate system prompts to force victims into providing their system password. Stolen session cookies enable attackers to bypass multi-factor authentication by hijacking active sessions. The campaign uses client-side JavaScript to filter victims by user-agent, directing desktop users to OS-specific payloads while ignoring mobile devices. Latest macOS updates include native terminal security warnings designed to alert users against pasting potentially malicious commands.