Multiple reports describe ClickFix-style lures used to deliver a macOS information-stealing malware aimed at cryptocurrency theft and credential compromise. The infection chain is described as first running a shell script that profiles the infected system, including collecting information about the host’s environment and CPU architecture. The script then retrieves a Go-based macOS malware payload designed to match the target machine’s architecture.
The reported malware targets several types of sensitive data. Sources say it steals cryptocurrency assets from infected systems, and it also captures browser-stored passwords. In addition, it attempts to access Apple iCloud Keychain information and cached credentials stored on the device. The overall behavior is presented as an infostealing operation that combines crypto-targeting with broader account credential harvesting.
While the accounts focus on macOS targeting and the malware’s data-theft capabilities, both reports align on the use of the ClickFix attack pattern, the delivery of a Go-based payload, and the specific categories of information being targeted.