Fake GitHub Lure Tricks macOS Users Into Stealer

The Hacker News · High sophistication
Last updated August 17, 2026

Researchers described AmnesiaStealer, a macOS info-stealer spread through a counterfeit “Download for macOS” page that tricks users into pasting a command into Terminal. The malware steals passwords and browser session data, and can even give an attacker live, hidden control of the victim’s browser sessions.

Key findings

  • Distributed through a counterfeit GitHub download page titled “Download for macOS,” using a ClickFix-style copy/paste lure.
  • Victims are instructed to paste a Base64-encoded command into macOS Terminal, which triggers a multi-stage install from a remote server.
  • The stealer prompts for the macOS system password “under the guise of an installer,” validates it locally, and loops until correct.
  • Harvests Keychain, Chromium browser data (cookies/logins/history/etc.), Apple Notes, Telegram, and files from common user folders.
  • Includes an on-demand second stage (“remote_stream”) that gives the operator live, hidden control of the victim’s authenticated browser sessions via Chrome DevTools Protocol.
  • Configuration includes a clipper module option and lists a C2 endpoint: debug.allllowef[.]space/send/.

Who’s being targeted

  • Commonly targeted roles: General employees, IT, Developers, Finance.
  • Affected industries: Cross-industry (macOS users).
  • Attack channels: website, physical.
  • Impersonated: A “verified publisher” on a GitHub download page, Installer / macOS system prompt.

Awareness takeaways

  • Treat any site that tells you to paste a command into Terminal as high risk; stop and verify via official vendor channels.
  • Be suspicious of installer password prompts that appear unexpectedly or keep repeating, this can be a password-harvesting trick.
  • Emphasize that stolen browser sessions can let attackers act as the user without needing the password, report unusual logins and re-authentication prompts quickly.

Red flags to watch for

  • A download page instructs you to paste a command into Terminal to install software
  • Claims to be from a “verified publisher” but is a counterfeit page
  • Use of encoded (Base64) commands instead of a normal installer
  • Unexpected password prompt during an install initiated from a web command
  • Repeated prompts/looping until the ‘correct’ password is entered
  • Installer behavior that validates the password and continues prompting
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You land on a GitHub page: big title, “Download for macOS,” shiny “verified publisher” badge. Looks legit, right? This one’s AmnesiaStealer. It tells you: copy this Base64 command into Terminal. Then a fake installer pops up, looping “Incorrect password. Please try again.” until you give your real macOS password. Once it has that, AmnesiaStealer quietly raids your Keychain, Chrome cookies and logins, Apple Notes, Telegram, and even lets someone drive your live browser sessions in the background, no password needed. Aha rule: if any “Download for macOS” page tells you to paste a command into Terminal, stop. Don’t run it, report it to IT Security and grab the app from the official site instead.

Similar attacks

Fake GitHub “ClickFix” Spreads macOS AmnesiaStealer

Fake GitHub “ClickFix” Spreads macOS AmnesiaStealer

Researchers say a real macOS malware campaign is using “ClickFix” social engineering to trick users into installing an infostealer called AmnesiaStealer. Victims are lured to a counterfeit GitHub download page that encourages them to copy/paste a Terminal command, which then downloads and runs the…

August 14, 2026
Fake GitHub Page Tricks Mac Users Into Malware

Fake GitHub Page Tricks Mac Users Into Malware

Researchers found a real macOS malware campaign that uses a fake GitHub download page to convince users to paste a command into Terminal and enter their Mac password. The malware then steals credentials, cookies, and files, and can even turn the victim’s Chromium browser into a remotely controlled…

August 17, 2026
ClickLock Tricks Mac Users Into Pasting Malware

ClickLock Tricks Mac Users Into Pasting Malware

Researchers documented a real macOS data-stealing campaign that relies on social engineering instead of software bugs. Victims are sent to a fake “verification” page that tells them to copy and paste a command into Terminal, which silently installs a stealer and then pressures them to enter their…

July 16, 2026
ClickLock Tricks Mac Users Into Running Malware

ClickLock Tricks Mac Users Into Running Malware

A macOS info-stealing malware called ClickLock Stealer uses a fake “Cloudflare verification” page to trick users into copying and running a Terminal command. It then steals browser, crypto wallet, and Keychain data and sends it to attackers via a Telegram bot, while killing processes to hide…

July 16, 2026
Poisoned AI Agent Files Turn Dev Tools Into Spies

Poisoned AI Agent Files Turn Dev Tools Into Spies

Researchers found real GitHub repositories containing poisoned AI-agent instruction/config files (like CLAUDE.md and .cursorrules) that silently tell coding assistants to steal prompts, environment variables, and credentials. The malicious instructions can trigger hidden commands (for example, curl…

August 4, 2026
Job Offer & Doc-Link Phishing Drive Real Breaches

Job Offer & Doc-Link Phishing Drive Real Breaches

This weekly threat bulletin describes real incidents where attackers used human manipulation to break in, including social engineering at Levi Strauss and a Microsoft 365 credential-theft phish at defense supplier IEH. It also highlights a Lazarus-linked campaign using fake job offers and…

August 17, 2026