macOS Help Content Now Delivers Stealers via Terminal
macOS users do not need to install a suspicious app to get hit here. This campaign turns help content into the delivery path, getting victims to run malicious Terminal commands that load stealers and bypass the normal file-based defenses most teams watch for.
Microsoft says the activity has shifted from earlier .dmg-based delivery to ClickFix-style instructions embedded in user-driven sites. The payloads include Macsync, Shub Stealer, and AMOS, and they steal iCloud data, Keychain entries, media files, and crypto wallet keys; some variants also replace legitimate wallet apps with trojanized copies.
The forward risk is broader than one infostealer family. Any guidance or content that convinces a user to paste commands into Terminal can become a malware launcher, and a clean app inventory may no longer mean a clean Mac.