Security researchers have discovered new infostealing macOS malware delivered via ClickFix social engineering attacks.
Managed detection and response (MDR) specialist Huntress said that it came across the malware in June 2026.
“In a ClickFix attack, the computer's user is presented with a popup window that appears to be a form of CAPTCHA prompt,” it noted.
“The window instructs the target to copy the text of a long command string and to paste it into the Terminal application on the computer. The command string typically downloads and executes the initial stage of the attack.”
Read more on ClickFix: ClickFix Attacks Surge 517% in 2025
In this particular attack, the command pulled a Bash profiler/loader that collected system details, then fetched a Mac-native Mach-O payload matched to the victim's processor architecture.
“Mach-O is the executable format used by macOS, and in this case the Go-based stealer was built to scrape browser password stores, Apple Keychain data, and cached credentials from the infected system,” the blog post continued.





