Malware · 171 giorni fa
Pagine di verifica Cloudflare false inducono utenti macOS a incollare ed eseguire comandi in Terminal che installano un loader Nuitka. Il loader avvia un infostealer Python compilato con Nuitka, più difficile da analizzare rispetto a payload Python standard. L'infostealer raccoglie browser credentials, elementi del Keychain, wallet di criptovalute, segreti di sviluppo e screenshot; esfiltra i dati via HTTP POST verso un C2 e notifica gli operatori su Telegram.
2 fonti che coprono questa storia
New Infinity Stealer malware grabs macOS data via ClickFix lures
A new info-stealing malware named Infinity Stealer is targeting macOS systems with a Python payload packaged as an executable using the open-source Nuitka compiler.
Cloudflare-Themed ClickFix Attack Drops Infiniti Stealer on Macs
The infection chain includes a fake CAPTCHA page, a Bash script, a Nuitka loader, and the Python-based infostealer.
Part of the PlainSec briefing for 2026-03-29