ClickFix Tricks Mac Users Into Running Stealer

Security Affairs · Medium sophistication
Last updated August 19, 2026

Microsoft describes a real macOS data-stealing campaign (MacSync Stealer) that relies on social engineering rather than software exploits. Victims are tricked into pasting/running commands in Terminal, which downloads the payload and ultimately steals passwords, keys, and wallet data, then uploads it in chunks to rotating attacker domains.

Key findings

  • The campaign uses social engineering (ClickFix) to trick users into pasting/running Terminal commands (no exploit required).
  • The payload is downloaded via curl from a path pattern like "/curl/[token]" and then decoded/unpacked using native macOS tools.
  • Stolen data includes Keychain data, browser passwords/cookies, SSH keys, AWS credentials, Kubernetes configs, and crypto wallet data (Ledger/Trezor).
  • Exfiltration is performed via chunked HTTP PUT uploads with parameters like upload_id, chunk_index, and total_chunks, even as domains rotate.
  • Microsoft linked 30+ domains to the same operation by tracking repeatable network/request behaviors instead of domain names.

Who’s being targeted

  • Commonly targeted roles: All macOS users, Developers, IT/Helpdesk, Cloud/DevOps (AWS/Kubernetes), Teams handling crypto assets/credentials.
  • Affected industries: Any organization with macOS endpoints (Mac fleets), Technology teams using cloud credentials (AWS/Kubernetes), Crypto/fintech users holding wallet credentials.
  • Attack channels: website.
  • Impersonated: A website/prompt claiming to provide a fix (exact brand not specified).

Awareness takeaways

  • Treat any request to paste/run Terminal commands as high-risk; verify with IT through a known channel before running anything.
  • Don’t rely only on blocking domains for protection, attackers can rotate infrastructure quickly; focus on behavior-based detections and user reporting.
  • Use extra safeguards for high-value credentials (Keychain, SSH keys, AWS, Kubernetes, crypto wallets) and minimize where they’re stored on endpoints.

Red flags to watch for

  • Any site/instructions asking you to paste commands into Terminal
  • Unexplained use of curl to fetch content from the internet
  • ‘Fix’ steps that require running scripts without IT verification
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

On a Mac and ever seen a website say, “To fix this issue, open Terminal and paste the following command”? That’s the ClickFix trick behind the MacSync Stealer campaign. No exploit, just you pasting a curl command into Terminal that quietly downloads and runs their payload. Once that shell session fires, it hunts for Keychain data, browser passwords and cookies, SSH keys, AWS and Kubernetes configs, even Ledger and Trezor wallet data, then uploads it in chunks to rotating domains. If any website tells you to paste a command into macOS Terminal, stop and send it to IT through our normal support channel before you run anything.

Similar attacks

MacSync Stealer Uses ClickFix Terminal Paste Trap

MacSync Stealer Uses ClickFix Terminal Paste Trap

Microsoft reports real-world macOS infections where victims were tricked into pasting commands into Terminal (a “ClickFix”-style social-engineering method). The malware then downloads a payload, steals credentials and other sensitive data (like Keychain and browser sessions), and uploads it in…

August 19, 2026
Mac ClickFix Trick Drops MacSync Data Stealer

Mac ClickFix Trick Drops MacSync Data Stealer

Microsoft reports MacSync Stealer infections that start when a user is tricked into pasting or running commands in macOS Terminal (a “ClickFix” style lure). Those commands use built-in tools like curl to download and run the payload, then the stealer collects credentials and sensitive files, stages…

August 18, 2026
Fake GitHub Lure Tricks macOS Users Into Stealer

Fake GitHub Lure Tricks macOS Users Into Stealer

Researchers described AmnesiaStealer, a macOS info-stealer spread through a counterfeit “Download for macOS” page that tricks users into pasting a command into Terminal. The malware steals passwords and browser session data, and can even give an attacker live, hidden control of the victim’s browser…

August 17, 2026
ClickFix Sites Trick Macs Into Running Malware Commands

ClickFix Sites Trick Macs Into Running Malware Commands

A real ClickFix campaign used 250+ lookalike domains and browser fingerprinting to show malware lures mainly to real macOS visitors while showing harmless decoys to scanners and researchers. Victims were pushed to copy and run an obfuscated command in macOS Terminal, which then downloaded and…

August 6, 2026
Fake GitHub “ClickFix” Spreads macOS AmnesiaStealer

Fake GitHub “ClickFix” Spreads macOS AmnesiaStealer

Researchers say a real macOS malware campaign is using “ClickFix” social engineering to trick users into installing an infostealer called AmnesiaStealer. Victims are lured to a counterfeit GitHub download page that encourages them to copy/paste a Terminal command, which then downloads and runs the…

August 14, 2026
OkoBot Tricks Crypto Users Into Running Commands

OkoBot Tricks Crypto Users Into Running Commands

Kaspersky reports an active OkoBot malware campaign targeting Windows users who manage cryptocurrency. Victims are lured via “ClickFix” fake-error pages that trick them into running PowerShell commands, and via GitHub repos posing as legitimate software downloads. The malware then steals wallet…

July 16, 2026