Malware · 171 days ago
Fake Cloudflare verification pages trick macOS users into running Terminal commands that install a Nuitka-compiled Python infostealer. The malware harvests browser credentials, Keychain items, cryptocurrency wallets, developer secrets and screenshots, then exfiltrates data to a C2 and notifies operators via Telegram.
2 sources covering this story
New Infinity Stealer malware grabs macOS data via ClickFix lures
A new info-stealing malware named Infinity Stealer is targeting macOS systems with a Python payload packaged as an executable using the open-source Nuitka compiler.
Cloudflare-Themed ClickFix Attack Drops Infiniti Stealer on Macs
The infection chain includes a fake CAPTCHA page, a Bash script, a Nuitka loader, and the Python-based infostealer.
Part of the PlainSec briefing for 2026-03-29