macOS Help Content Now Delivers Stealers via Terminal

macOS users do not need to install a suspicious app to get hit here. This campaign turns help content into the delivery path, getting victims to run malicious Terminal commands that load stealers and bypass the normal file-based defenses most teams watch for. Microsoft says the activity has shifted from earlier .dmg-based delivery to ClickFix-style instructions embedded in user-driven sites. The payloads include Macsync, Shub Stealer, and AMOS, and they steal iCloud data, Keychain entries, media files, and crypto wallet keys; some variants also replace legitimate wallet apps with trojanized copies. The forward risk is broader than one infostealer family. Any guidance or content that convinces a user to paste commands into Terminal can become a malware launcher, and a clean app inventory may no longer mean a clean Mac.

Part of the PlainSec briefing for 2026-05-06

Sources