Infiniti Stealer is a previously undocumented macOS infostealer, initially tracked as NukeChain and later confirmed through an exposed operator panel. It targets Mac users and is designed to steal sensitive data from macOS systems. Reported collection targets include credentials from Chromium-based browsers and Firefox, macOS Keychain entries, cryptocurrency wallet data, plaintext secrets in developer files such as .env, and screenshots captured during execution.
The malware is delivered through social engineering rather than exploitation. The campaign uses the ClickFix technique via a fake Cloudflare human verification page hosted on update-check[.]com. Victims are instructed to open Terminal, paste a provided command, and execute it. The infection chain consists of a Bash dropper, a Nuitka onefile Apple Silicon Mach-O loader, and a final Python 3.11 stealer payload compiled with Nuitka. The Bash dropper writes the next-stage binary to /tmp, removes the com.apple.quarantine attribute with xattr, executes the loader with nohup, passes the C2 server and authentication token as environment variables, deletes itself, and closes Terminal via AppleScript. The Stage-2 loader decompresses embedded data and launches the final payload, identified as UpdateHelper[.]bin.
Infiniti Stealer includes anti-analysis and evasion features. It checks for sandbox and virtualization environments including any.run, Joe Sandbox, Hybrid Analysis, VMware, and VirtualBox, and introduces randomized execution delays. Stolen data is exfiltrated via HTTP POST requests. After upload, the malware sends a Telegram notification to the operator and queues captured credentials for server-side password cracking.
The activity has been described as a structured, ongoing campaign and as the first documented macOS campaign combining ClickFix delivery with a Nuitka-compiled Python stealer. High-confidence indicators mentioned in the reporting include update-check[.]com, the C2 URL https://update-check[.]com/m/7d8df27d95d9, the panel domain infiniti-stealer[.]com, MD5 da73e42d1f9746065f061a6e85e28f0c for the dropper, SHA256 1e63be724bf651bb17bcf181d11bacfabef6a6360dcdfda945d6389e80f2b958 for the Stage-3 payload, the debug log path /tmp/.bs_debug.log, and the temporary path prefix /tmp/.2835b1b5098587a9XXXXXX.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
The page instructs the user to go to Spotlight on their Mac and search for the Terminal app. They are then instructed to paste a provided code into Terminal and hit return.
A fake verification page instructs the visitor to open Terminal, paste a command, and press Return. Once executed, the infection process begins immediately. | It spreads through a fake CAPTCHA page that tricks users into running a command themselves: a technique known as ClickFix. A fake verification page instructs the visitor to open Terminal, paste a command, and press Return.
Once decoded, the string resolves to a URL hosted on the same domain that returns the first stage dropper script.
The infection begins at update-check[.]com, which serves a convincing replica of a Cloudflare human verification page.
It then deletes itself and closes Terminal via AppleScript, ensuring the victim sees nothing unusual.
Before stealing any data, it checks whether it is running inside known analysis environments including any.run, Joe Sandbox, Hybrid Analysis, VMware, or VirtualBox.
Before stealing any data, it checks whether it is running inside known analysis environments including any.run, Joe Sandbox, Hybrid Analysis, VMware, or VirtualBox.
The stealer targets a wide range of sensitive data: Credentials from Chromium-based browsers and Firefox macOS Keychain entries
The malware is built to harvest login credentials from Chromium-based browsers and Firefox, collect macOS Keychain entries...
Before stealing any data, it checks whether it is running inside known analysis environments including any.run, Joe Sandbox, Hybrid Analysis, VMware, or VirtualBox.
5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Mac-focused stealer malware delivered through ClickFix-style social engineering that tricks users into pasting malicious code into Terminal, after which the payload is installed and is described as difficult to detect.
A macOS information stealer delivered via fake Cloudflare verification pages using ClickFix social engineering. It tricks users into pasting a command into Terminal, then executes a multi-stage infection chain to harvest browser credentials, macOS Keychain data, cryptocurrency wallets, screenshots, and plaintext secrets from .env files, exfiltrating the data via HTTP POST and notifying the operator through Telegram.
A macOS infostealer delivered via ClickFix-style social engineering through a fake CAPTCHA page. It uses a Bash dropper and a Nuitka-compiled Python loader/payload to steal browser credentials, macOS Keychain data, cryptocurrency wallets, plaintext secrets in developer files, and screenshots, then exfiltrates the data over HTTP POST and notifies operators via Telegram.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.