Skip to content

One pasted Terminal command opens the door to Mac crypto wallet theft

Researchers have uncovered Mac malware that can steal credentials and drain all or a selected percentage of a cryptocurrency wallet, in yet another reminder not to paste random commands from the internet into Terminal.

Open laptop on a desk displaying a large security warning dialog about an unexpected system error, asking for an administrator password, with a Huntress logo and a prominent blue Recover buttonNew malware via ClickFix

The Go-based malware arrived through a ClickFix attack, which disguises a malicious instruction as a CAPTCHA or error message. Instead of exploiting macOS, the attackers persuaded the victim to run the command that installed their malware for them.

Once executed, a Bash script profiled the Mac and downloaded a payload built for either Apple Silicon or Intel hardware. It then deleted its temporary file, cleared the Terminal window and removed the command from shell history.

Security analysts at Huntress found the infection during a retrospective threat hunt in June on a monitored Mac that had been compromised approximately three months earlier. The security company published its findings on August 6.

Continue Reading on AppleInsider | Discuss on our Forums