AmnesiaStealer macOS malware uses fake GitHub downloads and ClickFix prompts to steal passwords and hijack browser sessions

A newly reported macOS malware called AmnesiaStealer is being used to steal passwords, browser data, notes, and files from Apple users who are tricked into pasting commands into Terminal from a fake GitHub download page. Jamf says the Rust-based infostealer arrives in a multi-stage ClickFix chain, copies login and data-protection keychains, targets Safari plus Chromium-based browsers including Chrome, Brave, Arc, and Edge, installs a LaunchDaemon for persistence, and can on command launch a hidden headless browser for live remote control. It also attempts Transparency, Consent, and Control bypasses, including use of CVE-2020-9771, to access Safari cookies and full disk data.
Why it matters: This can let attackers steal saved credentials and take over active web sessions on Macs, not just copy files. Mac users and organizations should warn users not to paste terminal commands from websites, hunt for fake GitHub lures and LaunchDaemon persistence, and reset credentials and session cookies if compromise is suspected.

Sources

New AmnesiaStealer macOS malware hijacks browser sessions via remote control
Bill Toulas 2026.08.16 97% relevant
This article directly updates the same AmnesiaStealer campaign and adds concrete technical detail about its remote browser-control module, including profile duplication into a headless Chromium instance, WebSocket-based operator control, and targeted browsers and stolen data types.
AmnesiaStealer macOS Malware Steals Data, Controls Browser Sessions
Ionut Arghire 2026.08.14 100% relevant
This article establishes a distinct new malware story centered on the AmnesiaStealer family, its fake GitHub and ClickFix delivery chain, and its unusual browser-session remote-control capability on macOS.
← Back to all stories