AmnesiaStealer Malware Targets macOS Web Browsers
Hackers are pushing AmnesiaStealer malware to macOS users to hijack Chromium browsers and steal data via ClickFix attacks.

Stock photo for illustration only, not from the actual event
- AmnesiaStealer malware targets macOS users to hijack browser sessions.
- It can access 16 Chromium-based browsers and crypto wallets.
- Distributed via fake GitHub pages featuring Verified Publisher tags.
- Protection relies on avoiding untrusted Terminal execution commands.
Hackers are pushing a new infostealing malware to macOS users that is capable of hijacking active sessions in Google Chrome, Microsoft Edge, and a variety of other browsers built on Chromium. Named AmnesiaStealer, this malicious software grants remote control over your browser while harvesting extensive personal data, making it critical to recognize the campaign and secure your device.
As BleepingComputer reports, AmnesiaStealer can copy a victim's Chromium profile, allowing it to collect data across 16 Chromium-based web browsers, access authenticated sessions, and control them remotely. This means threat actors can navigate websites, export or import cookies, access online portals, and grab saved logins, browsing history, bookmarks, extensions, and cryptocurrency wallet data. Furthermore, AmnesiaStealer can capture your macOS password, gain access to keychain data, Apple Notes, Telegram sessions, documents, and system information.
ClickFix attacks represent an evolving social engineering trend where attackers trick users into executing malicious scripts themselves. By disguising payloads as routine error resolutions, CAPTCHA verifications, or technical prompts, fraudsters bypass traditional security perimeters because the user willingly grants administrative or execution privileges.
Researchers at security firm Jamf discovered that hackers are distributing the malware through a password-protected ZIP archive hosted on a fake GitHub page, acquiring deep system access once users execute a Terminal command that downloads and installs the payload. This ongoing campaign mirrors previously identified Atomic and MacSync infostealers.

Stock photo for illustration only, not from the actual event
The most effective way to shield yourself from AmnesiaStealer is to remain vigilant against ClickFix attacks, which rely heavily on social engineering tactics to deliver malware to your device. Common deceptive tricks include fake error messages, fraudulent CAPTCHA forms, and command prompts that install malicious payloads designed to spy on your activities, steal sensitive data, and hijack your machine.
Threat actors rely on the assumption that you will believe these commands are entirely harmless, such as downloading legitimate software, or that you might not fully understand what is being executed on your system. Therefore, you should maintain extreme skepticism toward any prompts found online and never execute commands in Terminal originating from non-official sources. Note that the fake GitHub page distributing AmnesiaStealer features a Verified Publisher tag to deceive users into trusting it. Fraudsters also attempt to impersonate legitimate corporations through tech support scams, meaning you should never copy and paste commands into your system dialog even if you believe you are interacting with an authentic business or service.
Source: Lifehacker
Found something wrong in this article? Report an issue with this article
Comments
Leave a Comment