Threats · 158 days ago
macOS defenses that warn users about suspicious Terminal commands can be bypassed by abusing Script Editor, a trusted preinstalled app, to run malicious commands without explicit Terminal interaction. This breaks the assumption that Terminal-based warnings cover all ClickFix attack paths and means standard detection methods miss this delivery vector.
Jamf observed active delivery of Atomic Stealer malware through fake Apple-themed disk-cleanup web pages that use an applescript:// link to open Script Editor with a prefilled malicious script. This script runs obfuscated commands that download and execute the malware entirely in memory, avoiding Terminal prompts and user-typed shell commands. The attack targets any Mac user who follows these web-based cleanup instructions, leveraging a legitimate macOS app as the execution channel.
This campaign shows that ClickFix mitigations focused on Terminal execution warnings are insufficient because attackers can use trusted macOS apps like Script Editor to run harmful commands. The risk persists until controls address this broader execution path, especially in environments relying on user prompts and Terminal-based detection.
5 sources covering this story
ClickFix campaign delivers Mac malware via fake Apple page - Help Net Security
A new ClickFix-style attack targeted Mac users via a fake Apple-themed webpage offering instructions on how to "reclaim disk space."
Atomic Stealer MacOS ClickFix Attack Bypasses Apple Security Warnings
macOS 26.4 update introduced security warnings into Terminal to prevent ClickFix attacks, so attackers have shifted to Script Editor instead
New ClickFix variant bypasses Apple safeguards with one‑click script execution
Jamf finds a ClickFix variant that swaps copy-paste Terminal lures for Script Editor execution, tightening delivery of Atomic Stealer.
New macOS stealer campaign uses Script Editor in ClickFix attack
A new campaign delivering the Atomic Stealer malware to macOS users abuses the Script Editor in a variation of the ClickFix attack that tricked users into executing commands in Terminal.
Risky Bulletin: Apple adds ClickFix warning to macOS terminal
Apple adds a ClickFix warning to macOS, Handala hacks Kash Patel's personal email, Balancer crypto platform shuts down after last year’s h [Read More
Part of the PlainSec briefing for 2026-04-11