Security firm Group-IB reports a new macOS malware campaign, “ClickLock Stealer,” that coerces victims into giving up passwords and access to stored credentials. According to Group-IB, the attack does not rely on exploits or elevated privileges. Instead, it starts after a victim copies and runs a command provided via a deceptive web page, described as a fake “ClickFix” page that mimics Cloudflare-style verification or browser checks. The page instructs the user to paste a command into Terminal.

Once executed, the script downloads additional components and displays terminal-based “loading” behavior resembling a Cloudflare progress indicator. If the victim declines an initial password prompt, the malware makes the Mac difficult to use: it repeatedly terminates visible applications while the prompt remains on screen, and it suppresses macOS security notifications for several hours. If the victim enters the password, the malware prompts for permission to allow access to a Keychain item, after which it can obtain Chrome’s “Safe Storage” encryption key used to protect saved passwords and cookies. Group-IB says the malware then collects browser credentials, password manager data, Keychain contents, and cryptocurrency wallet information, and exfiltrates data to a Telegram bot. It also installs a backdoor disguised as an iCloud process. Group-IB says the campaign has been active since May 2026 and identified at least 100 targets in 33 countries, with more than half in Europe. Apple has updated macOS Tahoe 26.4 to warn and block paste attempts into Terminal from websites, chats, or messages until the user reviews them.