Atomic Infostealer is an information-stealing malware targeting macOS. The provided content states it has been distributed via fake GitHub repositories and disguised as downloads for popular software including LastPass, 1Password, After Effects, and Gemini. Reported infection vectors therefore include trojanized or deceptive software downloads hosted in fraudulent GitHub repositories. The content specifically warns that macOS users seeking these applications may instead download Atomic Infostealer. No specific threat actor, technical capabilities beyond its role as an infostealer, targeted industries, or concrete indicators of compromise are provided in the source content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
macOS information stealer distributed via fake GitHub repositories masquerading as legitimate tools.
Atomic Infostealer is a malware targeting MacOS users, designed to steal sensitive information such as credentials and data from infected systems. It is distributed via malicious GitHub pages masquerading as legitimate software downloads.
An information-stealing malware distributed via GitHub repositories targeting macOS users.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.