A newly reported macOS malware called AmnesiaStealer is being used to steal passwords, browser data, notes, and files from Apple users who are tricked into pasting commands into Terminal from a fake GitHub download page. Jamf says the Rust-based infostealer arrives in a multi-stage ClickFix chain, copies login and data-protection keychains, targets Safari plus Chromium-based browsers including Chrome, Brave, Arc, and Edge, installs a LaunchDaemon for persistence, and can on command launch a hidden headless browser for live remote control. It also attempts Transparency, Consent, and Control bypasses, including use of CVE-2020-9771, to access Safari cookies and full disk data.
Why it matters: This can let attackers steal saved credentials and take over active web sessions on Macs, not just copy files. Mac users and organizations should warn users not to paste terminal commands from websites, hunt for fake GitHub lures and LaunchDaemon persistence, and reset credentials and session cookies if compromise is suspected.
Bill Toulas
2026.08.16
97% relevant
This article directly updates the same AmnesiaStealer campaign and adds concrete technical detail about its remote browser-control module, including profile duplication into a headless Chromium instance, WebSocket-based operator control, and targeted browsers and stolen data types.
Ionut Arghire
2026.08.14
100% relevant
This article establishes a distinct new malware story centered on the AmnesiaStealer family, its fake GitHub and ClickFix delivery chain, and its unusual browser-session remote-control capability on macOS.
← Back to all stories