A new variant of malware targeting macOS systems has been discovered, designed to steal cryptocurrency, passwords, and other sensitive information. This malware is particularly concerning for users involved in cryptocurrency transactions, as it can easily siphon off digital assets. Researchers have identified that the malware is capable of harvesting a wide array of personal data, raising alarms about the security of macOS users. With the growing popularity of cryptocurrencies, this incident underscores the need for enhanced security measures among users to protect their digital wallets and personal information. Users should remain vigilant and consider implementing additional security practices to safeguard against such attacks.
Articles tagged "macOS"
Found 40 articles
A new variant of the XCSSET malware has emerged, specifically targeting macOS developers by exploiting compromised Xcode projects and GitHub repositories. This malware is designed to infiltrate the development environment, potentially affecting thousands of users who download these compromised projects. Researchers have identified that the malware can steal sensitive information, including user credentials and private data, which poses a significant risk to both developers and their end users. As this malware spreads, it raises concerns about the security of development tools and the integrity of software supply chains. Developers are urged to be vigilant about the sources of their code and to implement security measures to protect their environments.
The Hacker News
Researchers have linked a new macOS malvertising campaign to North Korean actors, who are using deceptive tactics to deliver malware. The attackers redirect users to fake web pages that mimic legitimate macOS update screens, tricking them into thinking they need to install an update. Once users interact with these screens, malware is installed on their devices, specifically designed to steal cryptocurrency. This campaign is a continuation of the ongoing Contagious Interview campaign, raising concerns about the security of macOS users who may fall victim to these tactics. It serves as a reminder for users to be cautious of unexpected update prompts and to verify the legitimacy of software updates before proceeding.
Researchers have discovered a serious vulnerability in Anthropic's Claude Cowork that allows the AI agent to escape its Linux virtual machine (VM) environment. This flaw could enable the agent to access and manipulate files stored on the host Mac, potentially compromising user data. Approximately 500,000 macOS users are affected by this issue, as the vulnerability could be exploited by malicious actors. The implications are significant because it undermines the security measures designed to isolate applications from sensitive information on users' machines. Users are advised to stay alert for updates and patches that address this vulnerability.
The latest Malware Newsletter from Security Affairs includes several notable malware threats. One of these is CrashStealer, a C++ infostealer for macOS that masquerades as a crash reporter, targeting users to extract sensitive information. Another threat, Lucide Proxy, is exploiting student web proxies to create DDoS bots, potentially impacting educational institutions. Additionally, the AsyncAPI npm organization has been compromised, affecting about 2 million weekly downloads, which raises concerns for developers relying on these packages. Lastly, OkoBot is a sophisticated malware framework specifically designed to target cryptocurrency users, highlighting the ongoing risks in the digital currency space. These developments illustrate the evolving tactics of cybercriminals and the need for users and organizations to stay vigilant.
The Hacker News
A new piece of malware known as ClickLock Stealer is targeting macOS users by forcing them to input their login passwords. This infostealer operates by running a command in the Terminal that creates a fake system dialog asking for the password. If the victim cancels this request, the malware repeatedly kills various applications—including Finder and Terminal—every 210 milliseconds until the password is provided. Once the victim logs in again, the malware installs two LaunchAgents, allowing it to operate silently in the background. This type of attack is particularly concerning as it manipulates user behavior to extract sensitive information, highlighting the need for users to be cautious about unexpected prompts and commands.
Researchers have identified a new malware targeting macOS systems called CrashStealer, designed to steal sensitive information from compromised devices. What sets CrashStealer apart from other malware is its use of native C++ for implementation, rather than the more common AppleScript or Objective-C methods. This malware can validate the victim's login password locally, making it harder to detect. The use of a notarized dropper allows it to bypass Apple's Gatekeeper security checks, increasing its chances of successfully infecting systems. Users of macOS should be cautious and ensure their devices are protected against such threats, as this malware can lead to significant data breaches.
SCM feed for Latest
QuimaRAT is a new type of malware that can target multiple operating systems, including Windows, Linux, and macOS. It operates on a modular architecture, which means it can expand its capabilities through encrypted plugins that are delivered via a command-and-control infrastructure. This flexibility allows attackers to adapt the malware for various malicious purposes. The versatility of QuimaRAT raises concerns for users across different platforms, as it poses a significant risk to both personal and organizational security. Companies and individuals should be vigilant and consider implementing security measures to protect their systems from this evolving threat.
Researchers from Jamf Threat Labs have identified a new malware targeting macOS users, named PamStealer. This information stealer masquerades as a legitimate application called Maccy, which is a popular open-source clipboard manager. By distributing a compiled AppleScript file that looks legitimate, PamStealer tricks users into downloading it. Once installed, it seeks to extract sensitive information, including Mac login passwords. This incident is concerning for Mac users, as it highlights the ongoing risks posed by malware that exploits trusted applications to gain access to personal data.
Help Net Security
Attackers are currently exploiting a vulnerability in SimpleHelp, identified as CVE-2026-48558, which allows for an authentication bypass. This vulnerability has been patched, but it is actively being used to deploy Djinn Stealer malware on victim systems. Djinn Stealer is a versatile piece of malware that targets various operating systems, including Windows, macOS, and Linux. It collects sensitive credentials from a wide range of applications, including cloud services, source control, and cryptocurrency wallets. The situation poses a significant risk to users of SimpleHelp, particularly managed service providers, as the malware can compromise sensitive data and systems.
Hackers are taking advantage of a serious vulnerability (CVE-2026-48558) in SimpleHelp, a remote support software, to deploy a new type of malware known as Djinn Stealer. This malware is capable of stealing information across multiple operating systems, including Windows, macOS, and Linux. Users of SimpleHelp are at risk as the flaw allows attackers to infiltrate systems and extract sensitive data without detection. The emergence of this undocumented malware raises concerns about the security of remote support tools, as they are commonly used by businesses and individuals for remote access. It is crucial for users to remain vigilant and apply any necessary updates to protect their information.
Cybersecurity researchers have identified two hijacked npm packages and several compromised Go packages that are being used to deliver a Python-based information stealer to affected systems. This malware targets Windows, Linux, and macOS devices, making it a broad threat to developers and users of these platforms. Notably, the attack circumvents common npm execution paths, which may be an effort to bypass security measures introduced in npm version 12. The presence of these malicious packages poses a significant risk, as they could lead to unauthorized data access and theft. Developers and users need to be vigilant and ensure they are not using these compromised packages in their projects.
A recently discovered flaw in macOS allows standard users to disable Endpoint Detection and Response (EDR) and Mobile Device Management (MDM) features, which are critical for maintaining device security and management. This vulnerability could be exploited by malicious actors to weaken security controls, making it easier for them to execute attacks or gain unauthorized access to sensitive data. All macOS versions that support EDR and MDM functionalities are affected. Organizations using these features should be particularly vigilant, as the ability for unauthorized users to disable such protections can lead to significant security risks. As of now, there is no indication that this vulnerability is being actively exploited in the wild, but the potential for misuse remains a concern for IT departments.
Help Net Security
Homebrew, the popular package manager for macOS, is enhancing its security with the introduction of a new requirement for third-party taps. Starting with version 6.0.0, any tap and its associated formula or cask must be explicitly trusted before the Ruby code is executed. This change aims to mitigate risks associated with running unverified code from external sources, which previously could execute without any restrictions. Official Homebrew taps will remain trusted by default, but users will now have options to manage trust levels for additional taps. This move is significant for users who rely on third-party software, as it adds an extra layer of security against potentially malicious code.
The Hacker News
This week saw several cybersecurity incidents that highlight ongoing vulnerabilities in various systems. A zero-day vulnerability was discovered in Google Chrome, which could allow attackers to execute arbitrary code. Additionally, exploits affecting UniFi devices were reported, taking advantage of outdated software. Cybercriminals are also utilizing phishing kits that are increasingly easy to rent, making them more accessible to a wider range of attackers. Meanwhile, macOS systems are facing threats from new data-stealing malware, and a flaw in VPN services was identified, potentially exposing user data. These incidents remind users and organizations of the continuous need to update their software and remain vigilant against evolving cyber threats.