macOS ClickFix attacks deliver AppleScript stealers to snarf credentials, wallets
go.theregister.com Apr 22, 2026

macOS ClickFix attacks deliver AppleScript stealers to snarf credentials, wallets

AI-summarised brief · reviewed before publication

A ClickFix campaign targets macOS users, delivering an AppleScript-based infostealer that collects credentials and session cookies from browsers, cryptocurrency wallets, and extensions. The malware infects both Windows and macOS machines, with victims mainly in Asia's finance sector. Researchers observed the campaign last month, with similar instances seen recently. The malware uses a client-side JavaScript to filter victims and load the AppleScript-based stealer.💡

💡 Why It Matters

  • · The campaign's ability to evade detection by targeting desktop users and using AppleScript highlights a significant vulnerability in macOS security.
  • · Latest macOS update include a feature to block ClickFix attacks, making it crucial for users to keep their operating system up-to-date.