← Back to feed
Threat Actors & CampaignsEmerging1 sourceAug 6, 2026 · 15:10via AppleInsider

One pasted Terminal command opens the door to Mac crypto wallet theft

Brief

Researchers have uncovered Mac malware that can steal credentials and drain all or a selected percentage of a cryptocurrency wallet, in yet another reminder not to paste random commands from the internet into Terminal.

New malware via ClickFix

The Go-based malware arrived through a ClickFix attack , which disguises a malicious instruction as a CAPTCHA or error message. Instead of exploiting macOS , the attackers persuaded the victim to run the command that installed their malware for them.

Once executed, a Bash script profiled the Mac and downloaded a payload built for either Apple Silicon or Intel hardware. It then deleted its temporary file, cleared the Terminal window and removed the command from shell history.

Read more on AppleInsider