Paste-to-Terminal Turns Macs Into Their Own Installers
The risky part here is the user, not the browser. A web page that looks like a macOS toolkit setup prompts the victim to paste a command into Terminal, and that turns the victim's own shell into the installer for AMOS stealer.
The lab reproduction showed the same paste step run twice, which repeated the initial infection traffic and left two persistent copies on the host. The malware landed in user-writable areas, including Library/Application Support and /tmp, so a simple browser block or one-file cleanup misses the shape of the infection.
That makes manual command-paste lures a better delivery path than a browser exploit for defenders to watch. It also means repeated execution can leave more than one foothold behind, which makes remediation and forensics more work than deleting a single artifact.