Fake GitHub Page Tricks Mac Users Into Malware

CSO Online · High sophistication
Last updated August 17, 2026

Researchers found a real macOS malware campaign that uses a fake GitHub download page to convince users to paste a command into Terminal and enter their Mac password. The malware then steals credentials, cookies, and files, and can even turn the victim’s Chromium browser into a remotely controlled session for the attacker.

Key findings

  • Attackers used a ClickFix-style fake GitHub download page to trick users into pasting a Terminal command and entering their Mac password.
  • The command pulls a shell script that downloads a password-protected ZIP containing the main malware payload.
  • The malware steals credentials and sensitive data including Keychain data, browser data, Apple Notes, Telegram session information, and files.
  • A later stage can provide covert, interactive remote control of the victim’s Chromium browser via a WebSocket-connected module, including exporting cookies.
  • The fake site mimicked GitHub branding (dark theme, Octocat, and a “Verified Publisher” badge) to appear trustworthy.

Who’s being targeted

  • Commonly targeted roles: All macOS users, Developers/Engineering, IT support and endpoint teams, Security awareness training participants.
  • Affected industries: Any organization with macOS endpoints, Technology/Software teams, Professional Services.
  • Attack channels: website.
  • Impersonated: GitHub (fake download page / ‘Verified Publisher’).

Awareness takeaways

  • Treat any site that asks you to paste commands into Terminal as a high-risk scam and stop immediately.
  • Don’t trust branding (dark theme, logos, ‘Verified’ badges) as proof a download page is legitimate, verify the URL and source independently.
  • If prompted for your Mac password during a web ‘download’ workflow, assume compromise and report it, attackers may be trying to capture credentials.
  • Already-signed-in browser sessions are valuable, protect them and watch for suspicious browser behavior because attackers may reuse your existing access.

Red flags to watch for

  • A website asks you to install software by pasting commands into Terminal
  • Brand trust signals (e.g., ‘Verified Publisher’ badge) are used to rush you into compliance
  • Password-protected download/archive and nonstandard install steps for a normal ‘download’
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You’re on a GitHub-looking page, dark theme, Octocat, even a “Verified Publisher” badge… and it says: Download for macOS. But instead of a normal app download, the page tells you: open Terminal, paste this command, then enter your Mac password. That’s the AmnesiaStealer trick, real malware from a fake GitHub download flow. Once you run it, a hidden script pulls a password-protected ZIP, drops malware, and starts raiding Keychain, browser data, Apple Notes, Telegram sessions, even turning your Chromium browser into a remotely controlled session using your cookies. If any website tells you to paste a command into Terminal and type your Mac password, stop right there and report it to security, treat it as a high‑risk scam.

Similar attacks

Fake GitHub “ClickFix” Spreads macOS AmnesiaStealer

Fake GitHub “ClickFix” Spreads macOS AmnesiaStealer

Researchers say a real macOS malware campaign is using “ClickFix” social engineering to trick users into installing an infostealer called AmnesiaStealer. Victims are lured to a counterfeit GitHub download page that encourages them to copy/paste a Terminal command, which then downloads and runs the…

August 14, 2026
Fake GitHub Lure Tricks macOS Users Into Stealer

Fake GitHub Lure Tricks macOS Users Into Stealer

Researchers described AmnesiaStealer, a macOS info-stealer spread through a counterfeit “Download for macOS” page that tricks users into pasting a command into Terminal. The malware steals passwords and browser session data, and can even give an attacker live, hidden control of the victim’s browser…

August 17, 2026
HBO Max Reddit Account Hijacked for ClickFix Malware Ads

HBO Max Reddit Account Hijacked for ClickFix Malware Ads

Attackers took over the verified official HBO Max Reddit account and used it to run a 48-hour wave of malicious ads. The ads sent people to lookalike download sites that tricked them into copying and running commands, leading to information-stealing malware on both macOS and Windows. Researchers…

September 15, 2026
ClickLock Tricks Mac Users Into Running Malware

ClickLock Tricks Mac Users Into Running Malware

A macOS info-stealing malware called ClickLock Stealer uses a fake “Cloudflare verification” page to trick users into copying and running a Terminal command. It then steals browser, crypto wallet, and Keychain data and sends it to attackers via a Telegram bot, while killing processes to hide…

July 16, 2026
NGOs Lured via Donation Form Into Chrome 0-Day Chain

NGOs Lured via Donation Form Into Chrome 0-Day Chain

Researchers reported two China-linked groups targeting NGOs with spear-phishing that led victims through a legitimate U.S. university website before redirecting them to attacker infrastructure. The attackers used a chained Chrome/Windows exploit to take control, then deployed different payloads,…

September 15, 2026
Claude Linked to Real Phishing and Credential Theft

Claude Linked to Real Phishing and Credential Theft

Anthropic reports multiple real-world threat groups used Claude to support cyber operations, including credential harvesting and data theft across many victims. The report includes specific, simulation-ready lures such as a fake ESET NOD32 login portal that sends stolen passwords to Telegram and a…

September 11, 2026