SHub Stealer is a macOS-focused infostealer distributed in multiple social-engineering campaigns, most prominently ClickFix-style operations that trick users into executing malicious commands through Terminal or, in newer variants, Script Editor. It has been observed alongside other macOS stealers such as Atomic macOS Stealer (AMOS) and MacSync, and later builds have been tracked under the name Reaper. Delivery has relied on fake troubleshooting pages, impersonated software brands and utilities, bogus download portals, and malicious pages posing as trusted products or updates.
The malware typically uses a staged shell-to-AppleScript execution chain and includes geofencing logic that aborts on systems configured with Russian or CIS-related keyboard layouts. It commonly presents a fake macOS password prompt and validates entered credentials locally with dscl before proceeding. Confirmed theft targets include browser credentials, cookies, autofill data, Safari data, Firefox data, Chromium-family browser stores, macOS Keychain contents, iCloud-related data, Apple Notes, Telegram session data, shell history, documents, and extensive cryptocurrency wallet data from both browser extensions and desktop wallet applications.
A notable feature of SHub Stealer is its focus on cryptocurrency theft. Beyond stealing wallet files and extension data, it has been observed modifying legitimate desktop wallet applications, particularly Electron-based wallets, by replacing application resources with trojanized versions that capture passwords, seed phrases, and other wallet secrets when the user later opens the wallet. This behavior extends the compromise beyond the initial infection and can enable ongoing theft.
SHub Stealer also supports persistence through components disguised as legitimate Google update mechanisms, typically using LaunchAgent-based execution and a hidden updater-style backdoor that checks in periodically and can execute follow-on commands. Some reporting also describes exfiltration of stolen data through compressed archives and multipart uploads, as well as heartbeat-style bot registration for tasking. Later Reaper-tagged builds expanded collection with AMOS-style document theft modules and continued the use of fake software and update branding to reduce suspicion.
The malware has been associated with broad criminal macOS targeting, including users searching for software, troubleshooting guidance, streaming content, or cryptocurrency tools. Observed victim themes and lure design indicate particular interest in credential-rich and financially valuable users, including cryptocurrency holders and technically proficient macOS users.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
28 distinct techniques documented for this family, organized by ATT&CK tactic.
The updated build, now called Reaper, spreads through fake websites that impersonate popular software... It uses a fake webpage to silently open your Mac’s Script Editor, pre-loaded with malicious code, and all a user has to do is click one button to unknowingly launch the infection.
Initial commands leverage curl to fetch obfuscated payloads, which are piped directly into shell interpreters (bash/zsh), minimizing the disk footprint.
ClickFix variant that uses the applescript:// URL scheme to invoke the macOS Script Editor... This URL-encoded hyperlink runs a dual-track routine... while silently executing the curl command in the background to deliver an infostealer, bypassing Gatekeeper via user-coerced interaction.
Monitor Terminal usage : Alert on suspicious Terminal or shell sessions spawned by installers or user apps.
line 13 displays an obfuscated curl command that uses the native tr utility to dynamically decode a hidden URL
The campaign targets macOS users through fake utility and troubleshooting-themed lures.
The soft ask is an osascript dialog... whatever gets typed is checked against dscl /Local/Default -authonly first
Exfiltration efforts focus on high-value data, including ... messaging session tokens (Telegram/Discord)
Earlier builds could already steal browser data, macOS Keychains, iCloud account data, and Telegram session information. The new version goes much further, now targeting Chrome, Firefox, Brave, Edge, Opera, Vivaldi, Arc, and Orion browsers, along with their extensions.
The malware can collect Keychain data, browser information, iCloud data, media files, and cryptocurrency wallet credentials.
Exfiltration efforts focus on high-value data, including ... macOS Keychains
133 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
23 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a comparison point for similar macOS ClickFix infostealer behavior, specifically dscl-based password validation.
A named stealer malware observed in a macOS infection; the reference provides associated files, images, traffic capture, and IOCs for the infection.
A named stealer malware referenced in a macOS infection entry.
macOS stealer malware targeting browser credentials, Keychains, iCloud data, Telegram sessions, cryptocurrency wallets, and files. The Reaper variant uses fake software sites and an automated ClickFix-style infection chain via Script Editor, exfiltrates data with curl, modifies legitimate wallet apps to steal funds, and installs a persistent disguised backdoor.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.