LIVE NEWS
  • FDA Commissioner Makary praises staff in speech
  • California Suspends Enforcement of Law Requiring VCs to Report Diversity Data
  • Record monthly rise in petrol and diesel prices, says RAC
  • How Dow Jones is Affecting the Market Today
  • Scientists open 40-year-old salmon and find a surprising sign of ocean recovery
  • Global super-rich may have hidden $3.55tn from tax officials, says Oxfam | Tax havens
  • If chaplains are ‘officers second,’ which staff corps officers are next?
  • Astronauts can face ‘nearly lethal doses’ of solar radiation — so why launch Artemis II during the sun’s peak of activity? Space scientist Patricia Reiff explains.
Prime Reports
  • Home
  • Popular Now
  • Crypto
  • Cybersecurity
  • Economy
  • Geopolitics
  • Global Markets
  • Politics
  • See More
    • Artificial Intelligence
    • Climate Risks
    • Defense
    • Healthcare Innovation
    • Science
    • Technology
    • World
Prime Reports
  • Home
  • Popular Now
  • Crypto
  • Cybersecurity
  • Economy
  • Geopolitics
  • Global Markets
  • Politics
  • Artificial Intelligence
  • Climate Risks
  • Defense
  • Healthcare Innovation
  • Science
  • Technology
  • World
Home»Cybersecurity»Cloudflare-Themed ClickFix Attack Drops Infiniti Stealer on Macs
Cybersecurity

Cloudflare-Themed ClickFix Attack Drops Infiniti Stealer on Macs

primereportsBy primereportsMarch 29, 2026No Comments2 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Cloudflare-Themed ClickFix Attack Drops Infiniti Stealer on Macs
Share
Facebook Twitter LinkedIn Pinterest Email


macOS users are targeted in a fresh ClickFix campaign that uses a Cloudflare-themed verification page to deliver a Python-based information stealer, Malwarebytes reports.

The attack starts with a fake CAPTCHA page that serves a legitimate-looking Cloudflare human verification page asking visitors to paste and execute a command in Terminal.

Referred to as ClickFix, the technique relies on social engineering to trick users into executing malicious commands on their devices and has been widely used in attacks since August 2024, mainly against Windows users.

For more than half a year, however, attacks tailored for macOS have become increasingly convincing, and the variant observed by Malwarebytes is no different.

The fake verification page provides macOS users with specific instructions to open the Terminal and paste and execute a fake verification command that triggers malware execution.

Once the victim runs the command, a Bash script is fetched from a remote server. The script decodes an embedded payload, writes the second stage binary to a temporary folder, removes its quarantine flag, and executes it.

Advertisement. Scroll to continue reading.

The script also passes command-and-control (C&C) server and authentication tokens as environment variables, deletes itself, and closes the Terminal.

The binary dropped by the script is a loader compiled using Nuitka. The compiler transforms Python code into a native binary, making static analysis more difficult.

At runtime, the loader decompresses embedded data and launches the final payload, identified as the Infiniti Stealer malware.

The Python-based information stealer targets browser credentials, Keychain information, cryptocurrency wallets, secrets stored in developer files, and screenshots captured during execution.

The data is sent to the C&C via HTTP POST requests. Once the operation has been completed, the malware sends a notification to a Telegram channel and queues captured credentials to be cracked on the server.

For evasion, Infiniti Stealer relies on randomized execution delay and checks if the system is a known analysis environment.

“Infiniti Stealer shows how techniques that worked on Windows—like ClickFix—are now being adapted to target Mac users. It also uses newer techniques, like compiling Python into native apps, which makes the malware harder to detect and analyze. If this approach proves effective, we may see more attacks like this,” Malwarebytes notes.

Related: Over 100 GitHub Repositories Distributing BoryptGrab Stealer

Related: ‘SolyxImmortal’ Information Stealer Emerges

Related: North Korean Hackers Target macOS Developers via Malicious VS Code Projects

Related: MacSync macOS Malware Distributed via Signed Swift Application

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleMarket’s ability to forecast world in question
Next Article Gnosis and Zisk Unveil ‘Ethereum Economic Zone’ Framework
primereports
  • Website

Related Posts

Cybersecurity

CERT-UA Impersonation Campaign Spread AGEWHEEZE Malware to 1 Million Emails

April 1, 2026
Cybersecurity

Depthfirst Raises $80 Million in Series B Funding

April 1, 2026
Cybersecurity

Google fixes Chrome zero-day with in-the-wild exploit (CVE-2026-5281)

April 1, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Global Resources Outlook 2024 | UNEP

December 6, 20257 Views

The D Brief: DHS shutdown likely; US troops leave al-Tanf; CNO’s plea to industry; Crowded robot-boat market; And a bit more.

February 14, 20264 Views

German Chancellor Merz faces difficult mission to Israel – DW – 12/06/2025

December 6, 20254 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Latest Reviews

Subscribe to Updates

Get the latest tech news from FooBar about tech, design and biz.

PrimeReports.org
Independent global news, analysis & insights.

PrimeReports.org brings you in-depth coverage of geopolitics, markets, technology and risk – with context that helps you understand what really matters.

Editorially independent · Opinions are those of the authors and not investment advice.
Facebook X (Twitter) LinkedIn YouTube
Key Sections
  • World
  • Geopolitics
  • Popular Now
  • Artificial Intelligence
  • Cybersecurity
  • Crypto
All Categories
  • Artificial Intelligence
  • Climate Risks
  • Crypto
  • Cybersecurity
  • Defense
  • Economy
  • Geopolitics
  • Global Markets
  • Healthcare Innovation
  • Politics
  • Popular Now
  • Science
  • Technology
  • World
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms & Conditions
  • Disclaimer
  • Cookie Policy
  • DMCA / Copyright Notice
  • Editorial Policy

Sign up for Prime Reports Briefing – essential stories and analysis in your inbox.

By subscribing you agree to our Privacy Policy. You can opt out anytime.
Latest Stories
  • FDA Commissioner Makary praises staff in speech
  • California Suspends Enforcement of Law Requiring VCs to Report Diversity Data
  • Record monthly rise in petrol and diesel prices, says RAC
© 2026 PrimeReports.org. All rights reserved.
Privacy Terms Contact

Type above and press Enter to search. Press Esc to cancel.