Fake GitHub Page Tricks Mac Users Into Malware

CSO Online · High sophistication
Last updated August 17, 2026

Researchers found a real macOS malware campaign that uses a fake GitHub download page to convince users to paste a command into Terminal and enter their Mac password. The malware then steals credentials, cookies, and files, and can even turn the victim’s Chromium browser into a remotely controlled session for the attacker.

Key findings

  • Attackers used a ClickFix-style fake GitHub download page to trick users into pasting a Terminal command and entering their Mac password.
  • The command pulls a shell script that downloads a password-protected ZIP containing the main malware payload.
  • The malware steals credentials and sensitive data including Keychain data, browser data, Apple Notes, Telegram session information, and files.
  • A later stage can provide covert, interactive remote control of the victim’s Chromium browser via a WebSocket-connected module, including exporting cookies.
  • The fake site mimicked GitHub branding (dark theme, Octocat, and a “Verified Publisher” badge) to appear trustworthy.

Who’s being targeted

  • Commonly targeted roles: All macOS users, Developers/Engineering, IT support and endpoint teams, Security awareness training participants.
  • Affected industries: Any organization with macOS endpoints, Technology/Software teams, Professional Services.
  • Attack channels: website.
  • Impersonated: GitHub (fake download page / ‘Verified Publisher’).

Awareness takeaways

  • Treat any site that asks you to paste commands into Terminal as a high-risk scam and stop immediately.
  • Don’t trust branding (dark theme, logos, ‘Verified’ badges) as proof a download page is legitimate, verify the URL and source independently.
  • If prompted for your Mac password during a web ‘download’ workflow, assume compromise and report it, attackers may be trying to capture credentials.
  • Already-signed-in browser sessions are valuable, protect them and watch for suspicious browser behavior because attackers may reuse your existing access.

Red flags to watch for

  • A website asks you to install software by pasting commands into Terminal
  • Brand trust signals (e.g., ‘Verified Publisher’ badge) are used to rush you into compliance
  • Password-protected download/archive and nonstandard install steps for a normal ‘download’
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You’re on a GitHub-looking page, dark theme, Octocat, even a “Verified Publisher” badge… and it says: Download for macOS. But instead of a normal app download, the page tells you: open Terminal, paste this command, then enter your Mac password. That’s the AmnesiaStealer trick, real malware from a fake GitHub download flow. Once you run it, a hidden script pulls a password-protected ZIP, drops malware, and starts raiding Keychain, browser data, Apple Notes, Telegram sessions, even turning your Chromium browser into a remotely controlled session using your cookies. If any website tells you to paste a command into Terminal and type your Mac password, stop right there and report it to security, treat it as a high‑risk scam.

Similar attacks

Fake GitHub “ClickFix” Spreads macOS AmnesiaStealer

Fake GitHub “ClickFix” Spreads macOS AmnesiaStealer

Researchers say a real macOS malware campaign is using “ClickFix” social engineering to trick users into installing an infostealer called AmnesiaStealer. Victims are lured to a counterfeit GitHub download page that encourages them to copy/paste a Terminal command, which then downloads and runs the…

August 14, 2026
Fake GitHub Lure Tricks macOS Users Into Stealer

Fake GitHub Lure Tricks macOS Users Into Stealer

Researchers described AmnesiaStealer, a macOS info-stealer spread through a counterfeit “Download for macOS” page that tricks users into pasting a command into Terminal. The malware steals passwords and browser session data, and can even give an attacker live, hidden control of the victim’s browser…

August 17, 2026
ClickLock Tricks Mac Users Into Running Malware

ClickLock Tricks Mac Users Into Running Malware

A macOS info-stealing malware called ClickLock Stealer uses a fake “Cloudflare verification” page to trick users into copying and running a Terminal command. It then steals browser, crypto wallet, and Keychain data and sends it to attackers via a Telegram bot, while killing processes to hide…

July 16, 2026
Fake GitHub Lure Spreads AmnesiaStealer on macOS

Fake GitHub Lure Spreads AmnesiaStealer on macOS

Researchers describe AmnesiaStealer, a macOS infostealer spread via a convincing fake GitHub download page that tricks users into pasting a Terminal command. After installation, it uses an “Installer”-style password prompt to capture the Mac login password, steal browser and keychain data, and can…

August 14, 2026
Fake Teams Update Drops Remote-Access Tools

Fake Teams Update Drops Remote-Access Tools

Researchers reported a real phishing campaign (“Operation BlueDash”) that tricks users with a “secure document” lure and routes them to a fake Microsoft Store page that claims Microsoft Teams must be updated. The download installs legitimate remote access tools (Level RMM and ScreenConnect) so…

July 27, 2026
ClickLock Tricks Mac Users Into Pasting Malware

ClickLock Tricks Mac Users Into Pasting Malware

Researchers documented a real macOS data-stealing campaign that relies on social engineering instead of software bugs. Victims are sent to a fake “verification” page that tells them to copy and paste a command into Terminal, which silently installs a stealer and then pressures them to enter their…

July 16, 2026