One pasted Terminal command opens the door to Mac crypto wallet theft
AI-summarised brief · reviewed before publication
Researchers discovered a macOS malware that steals cryptocurrency wallet credentials and can drain all or a portion of the wallet. The threat, delivered via a ClickFix attack, tricks users into pasting a command that installs a Go-based payload. Once executed, a Bash script profiles the Mac, downloads a hardware‑specific binary, deletes its temporary file, clears the Terminal, and removes its command from shell history. Huntress identified the infection during a June threat hunt on a monitored Mac, publishing findings on August 6.
💡 Why It Matters
- · The attack demonstrates how social engineering can bypass macOS security, turning a single pasted command into a full wallet‑theft tool.
- · It underscores the need for users to verify command sources before execution.