One pasted Terminal command opens the door to Mac crypto wallet theft
Brief
Researchers have uncovered Mac malware that can steal credentials and drain all or a selected percentage of a cryptocurrency wallet, in yet another reminder not to paste random commands from the internet into Terminal.
New malware via ClickFix
The Go-based malware arrived through a ClickFix attack , which disguises a malicious instruction as a CAPTCHA or error message. Instead of exploiting macOS , the attackers persuaded the victim to run the command that installed their malware for them.
Once executed, a Bash script profiled the Mac and downloaded a payload built for either Apple Silicon or Intel hardware. It then deleted its temporary file, cleared the Terminal window and removed the command from shell history.
