Paste One Command, Lose Mac Passwords and Wallets

The dangerous part is not a fake file. It is a pasted Terminal command that can hand an attacker browser passwords, iCloud Keychain data, cached credentials, and crypto funds in one shot. The same lure also adapts the payload to the victim’s Mac architecture, so it works across Intel and Apple Silicon systems. The malware is a Go-based macOS stealer delivered through ClickFix-style lures. It profiles the host, fetches the matching Mach-O payload, steals saved logins and system credentials, and includes a wallet-draining routine that can siphon part or all of funds from Bitcoin, Litecoin, Dogecoin, Monero, Ethereum, and XRP wallets. That makes a compromised Mac more than a password problem. A user can lose enterprise access and personal crypto assets from the same interaction, and the fake system prompt gives the attacker a second chance to capture the Mac password as well.

Part of the PlainSec briefing for 2026-08-10

Every edition of this story: Paste One Command, Lose Mac Passwords and Wallets

Sources