Security researchers report that the SHub “Reaper” macOS infostealer uses impersonation and a multi-stage execution chain to trick users into running malicious code. According to SentinelOne and other reporting, the malware presents itself as legitimate software by spoofing brands associated with major technology companies, including Apple, Microsoft, and Google. The initial delivery and execution flow is described as evolving from earlier SHub campaigns that relied on “ClickFix” social-engineering tactics, such as prompting victims to paste commands. Instead, researchers say Reaper shifts toward an Apple script-based execution approach and uses fake installer themes to lure users.

After execution, Reaper focuses on stealing high-value data from common targets on macOS. Reported objectives include extracting browser information, credentials stored by password managers, and cryptocurrency wallet data. Researchers also say the malware establishes persistence, enabling continued access beyond the initial infection. Both sources characterize the attack as a backdoor-capable stealer rather than a one-time data grab, emphasizing the progression from user deception to staged compromise and ongoing control.