LIVE NEWS
  • Underground drug smuggling tunnel discovered from Tijuana to San Diego | US-Mexico Border
  • XRP Is The Clear Winner For Transactions, According To Peter Brandt
  • How AI-Native Security Will Reshape Enterprise Defense
  • Berkshire Hathaway buys Taylor Morrison for $6.8 billion. Buffett touts Abel’s deal-making
  • Learning from the Global South — Global Issues
  • Stocks Close Higher on Hopes for Continued US-Iran Ceasefire Negotiations
  • US court blocks Pentagon from removing transgender troops, for now
  • Paralympian could become first astronaut with disability to live and work in space
Prime Reports
  • Home
  • Popular Now
  • Crypto
  • Cybersecurity
  • Economy
  • Geopolitics
  • Global Markets
  • Politics
  • See More
    • Artificial Intelligence
    • Climate Risks
    • Defense
    • Healthcare Innovation
    • Science
    • Technology
    • World
Prime Reports
  • Home
  • Popular Now
  • Crypto
  • Cybersecurity
  • Economy
  • Geopolitics
  • Global Markets
  • Politics
  • Artificial Intelligence
  • Climate Risks
  • Defense
  • Healthcare Innovation
  • Science
  • Technology
  • World
Home»Cybersecurity»Cloudflare-Themed ClickFix Attack Drops Infiniti Stealer on Macs
Cybersecurity

Cloudflare-Themed ClickFix Attack Drops Infiniti Stealer on Macs

primereportsBy primereportsMarch 29, 2026No Comments2 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Cloudflare-Themed ClickFix Attack Drops Infiniti Stealer on Macs
Share
Facebook Twitter LinkedIn Pinterest Email


macOS users are targeted in a fresh ClickFix campaign that uses a Cloudflare-themed verification page to deliver a Python-based information stealer, Malwarebytes reports.

The attack starts with a fake CAPTCHA page that serves a legitimate-looking Cloudflare human verification page asking visitors to paste and execute a command in Terminal.

Referred to as ClickFix, the technique relies on social engineering to trick users into executing malicious commands on their devices and has been widely used in attacks since August 2024, mainly against Windows users.

For more than half a year, however, attacks tailored for macOS have become increasingly convincing, and the variant observed by Malwarebytes is no different.

The fake verification page provides macOS users with specific instructions to open the Terminal and paste and execute a fake verification command that triggers malware execution.

Once the victim runs the command, a Bash script is fetched from a remote server. The script decodes an embedded payload, writes the second stage binary to a temporary folder, removes its quarantine flag, and executes it.

Advertisement. Scroll to continue reading.

The script also passes command-and-control (C&C) server and authentication tokens as environment variables, deletes itself, and closes the Terminal.

The binary dropped by the script is a loader compiled using Nuitka. The compiler transforms Python code into a native binary, making static analysis more difficult.

At runtime, the loader decompresses embedded data and launches the final payload, identified as the Infiniti Stealer malware.

The Python-based information stealer targets browser credentials, Keychain information, cryptocurrency wallets, secrets stored in developer files, and screenshots captured during execution.

The data is sent to the C&C via HTTP POST requests. Once the operation has been completed, the malware sends a notification to a Telegram channel and queues captured credentials to be cracked on the server.

For evasion, Infiniti Stealer relies on randomized execution delay and checks if the system is a known analysis environment.

“Infiniti Stealer shows how techniques that worked on Windows—like ClickFix—are now being adapted to target Mac users. It also uses newer techniques, like compiling Python into native apps, which makes the malware harder to detect and analyze. If this approach proves effective, we may see more attacks like this,” Malwarebytes notes.

Related: Over 100 GitHub Repositories Distributing BoryptGrab Stealer

Related: ‘SolyxImmortal’ Information Stealer Emerges

Related: North Korean Hackers Target macOS Developers via Malicious VS Code Projects

Related: MacSync macOS Malware Distributed via Signed Swift Application

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleMarket’s ability to forecast world in question
Next Article Gnosis and Zisk Unveil ‘Ethereum Economic Zone’ Framework
primereports
  • Website

Related Posts

Cybersecurity

How AI-Native Security Will Reshape Enterprise Defense

June 2, 2026
Cybersecurity

Miasma Supply Chain Attack Compromises Red Hat npm Packages with Credential-Stealing Worm

June 1, 2026
Cybersecurity

Alleged Kimwolf Botmaster ‘Dort’ Arrested, Charged in U.S. and Canada – Krebs on Security

June 1, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Paxton’s win over Cornyn sets up high-stakes Texas clash with Talarico

May 28, 202616 Views

Global Resources Outlook 2024 | UNEP

December 6, 202510 Views

Texas Democrat Talarico claims voting laws are rigged ahead of Paxton race

May 28, 20269 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Latest Reviews

Subscribe to Updates

Get the latest tech news from FooBar about tech, design and biz.

PrimeReports.org
Independent global news, analysis & insights.

PrimeReports.org brings you in-depth coverage of geopolitics, markets, technology and risk – with context that helps you understand what really matters.

Editorially independent · Opinions are those of the authors and not investment advice.
Facebook X (Twitter) LinkedIn YouTube
Key Sections
  • World
  • Geopolitics
  • Popular Now
  • Artificial Intelligence
  • Cybersecurity
  • Crypto
All Categories
  • Artificial Intelligence
  • Climate Risks
  • Crypto
  • Cybersecurity
  • Defense
  • Economy
  • Geopolitics
  • Global Markets
  • Healthcare Innovation
  • Politics
  • Popular Now
  • Science
  • Technology
  • World
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms & Conditions
  • Disclaimer
  • Cookie Policy
  • DMCA / Copyright Notice
  • Editorial Policy

Sign up for Prime Reports Briefing – essential stories and analysis in your inbox.

By subscribing you agree to our Privacy Policy. You can opt out anytime.
Latest Stories
  • Underground drug smuggling tunnel discovered from Tijuana to San Diego | US-Mexico Border
  • XRP Is The Clear Winner For Transactions, According To Peter Brandt
  • How AI-Native Security Will Reshape Enterprise Defense
© 2026 PrimeReports.org. All rights reserved.
Privacy Terms Contact

Type above and press Enter to search. Press Esc to cancel.