Malware · 43 days ago
Jamf found a Rust-based macOS stealer, AmnesiaStealer, delivered in recent ClickFix attacks through a fake GitHub installer page. The malware targets passwords, keychains, Chromium-based browser data, and Safari cookies, then can switch into a browser-control module on demand.
That second module uses the Chrome DevTools Protocol, the same browser-inspection interface developers use, to launch a hidden copy of the victim’s browser and drive it in real time. In plain terms, the attacker is not just reusing stolen cookies later; they can act inside the already logged-in session while it is still live, which turns endpoint theft into account abuse.
The reach is broader than macOS itself: any environment that leans on browser-based SSO and open sessions can inherit the same risk if a user is lured into the paste-and-run flow. Static password resets and cookie changes may come after the fact, but they do not describe what may already have happened inside the session.
4 sources covering this story
New AmnesiaStealer macOS malware hijacks browser sessions via remote control
A new information-stealing malware called AmnesiaStealer, which targets macOS users via ClickFix attacks, includes a streaming module that allows the attacker to interactively control the victim's web browser.
Novel macOS Infostealer AmnesiaStealer Spread via ClickFix
AmnesiaStealer contains novel functions, including the attackers gaining remote control over the victim’s browser to steal cookie data
AmnesiaStealer macOS Malware Steals Data, Controls Browser Sessions
The Rust-based macOS infostealer harvests users’ passwords, keychain information, Chromium-based browser data, and Safari cookies.
AmnesiaStealer Hijacks Chromium Sessions to Give Attackers Live Browser Control on macOS
AmnesiaStealer uses a ClickFix lure to infect macOS, steal browser sessions, and give attackers live Chromium control via CDP.
Part of the PlainSec briefing for 2026-08-17