Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
credential-stealer-activityphishing-campaign-intelligenceinitial-access-methoddefense-evasion-method

ClickFix macOS Campaign Abuses Script Editor to Deploy Atomic Stealer

Updated 28d agoFirst seen Apr 9, 20269 sources

Researchers identified a ClickFix-style campaign targeting macOS users that swaps Terminal-based execution for Script Editor to bypass newer Apple protections. Victims are lured to fake Apple-themed pages such as “Reclaim disk space on your Mac,” which invoke the applescript:// URL scheme and open Script Editor with a pre-filled AppleScript. If the user runs it, the script conceals a malicious shell command that decodes a URL, uses curl with TLS certificate validation disabled, and pipes the response directly into zsh for in-memory execution.

The activity, discovered by Jamf Threat Labs, ultimately downloads and launches a Mach-O variant of Atomic Stealer, an infostealer built to harvest browser credentials, saved passwords, cryptocurrency wallets, and other sensitive data from macOS systems. Researchers said the campaign appears to be an adaptation to Apple’s paste-command scanning protections added in macOS 26.4 for Terminal abuse; while newer macOS versions also warn about unidentified scripts, the attack can still succeed if users follow the prompts. Reported infrastructure tied to the campaign includes dryvecar.com, storage-fixes.squarespace.com, and cleanupmac.mssg.me.

Share:
ClickFix macOS Campaign Abuses Script Editor to Deploy Atomic Stealer
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

8 events from the most recent confirmed update back to the earliest known activity.

8 EVENTS
Apr 9, 20262mo ago

Researchers link campaign to supporting infrastructure

Analysis tied the campaign to infrastructure including dryvecar.com, storage-fixes.squarespace.com, and cleanupmac.mssg.me. The operation was described as targeting macOS users to steal browser credentials, saved passwords, cryptocurrency wallets, and other sensitive data.

Jamf Threat Labs identifies Atomic Stealer macOS campaign in the wild

Jamf researchers documented an active campaign delivering a variant of Atomic Stealer through Script Editor on macOS. They reported that the script fetched remote content with curl using disabled TLS certificate validation, executed it in memory, and ultimately downloaded a Mach-O payload.

Attackers shift ClickFix delivery from Terminal to macOS Script Editor

After Apple’s Terminal-focused protections, attackers adapted their technique by using the applescript:// URL scheme to open Script Editor with a pre-filled malicious AppleScript. The lure used fake Apple-themed disk cleanup pages to socially engineer users into running the script.

Apple adds Terminal paste-scanning protections in macOS 26.4

Apple introduced protections in macOS 26.4 to scan pasted commands in Terminal and warn users about potentially suspicious activity. The new safeguards were intended to reduce abuse of Terminal-based social engineering techniques such as ClickFix-style attacks.

Mar 21, 20263mo ago

Netskope identifies separate ClickFix macOS campaign targeting Asian finance

Netskope Threat Labs reported an active ClickFix campaign targeting macOS users in Asia’s finance sector with an AppleScript-based infostealer. The attack used fake CAPTCHA prompts to trick victims into pasting a malicious curl command, then displayed a persistent fake macOS password dialog to steal valid credentials and extensive browser, Keychain, extension, and cryptocurrency wallet data.

MacOS ClickFix attacks deliver AppleScript stealers
Mar 4, 20264mo ago

Guardio reports fake 'Mac Storage Fix' Google Ads scam targeting macOS users

Guardio published research on a scam using fake 'Mac Storage Fix' lures promoted via Google Ads to target macOS users. The campaign appears to be an earlier stage of the social-engineering activity later associated with ClickFix-style macOS malware delivery.

Googled a Mac Storage Fix Lately? It May Be a Scam
Feb 12, 20264mo ago

Intego reports Matryoshka ClickFix macOS stealer via typosquatting

Intego reported a new 'Matryoshka' ClickFix variant targeting macOS users through typosquatting infrastructure to deliver a stealer. The report indicates the campaign was already using ClickFix-style social engineering against Mac users before the later Google Ads and Script Editor activity documented by other researchers.

Unpacking the New “Matryoshka” ClickFix Variant: Typosquatting Campaign Delivers macOS Stealer - The Mac Security Blog Matryoshka ClickFix Variant Delivers macOS Stealer via Typosquatting
Jan 1, 20266mo ago

Microsoft traces ClickFix macOS activity back to January 2026

Microsoft Defender researchers reported that ClickFix had been targeting macOS users since at least January 2026, marking an expansion of the technique beyond Windows. The campaign used fake disk-space, error, and utility-install prompts on blogs and user-driven platforms to trick users into pasting Terminal commands that delivered Macsync, Shub Stealer, or Atomic macOS Stealer.

ClickFix Campaign Evolves With Targeting Of MacOS Users
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

8 LINKEDOpen in app
Malware
1 linked
Affected products
3 linked
MacosTerminalApplescript
Organizations
4 linked
AppleJamfSquarespaceBleepingComputer
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.