Researchers identified a ClickFix-style campaign targeting macOS users that swaps Terminal-based execution for Script Editor to bypass newer Apple protections. Victims are lured to fake Apple-themed pages such as “Reclaim disk space on your Mac,” which invoke the applescript:// URL scheme and open Script Editor with a pre-filled AppleScript. If the user runs it, the script conceals a malicious shell command that decodes a URL, uses curl with TLS certificate validation disabled, and pipes the response directly into zsh for in-memory execution.
The activity, discovered by Jamf Threat Labs, ultimately downloads and launches a Mach-O variant of Atomic Stealer, an infostealer built to harvest browser credentials, saved passwords, cryptocurrency wallets, and other sensitive data from macOS systems. Researchers said the campaign appears to be an adaptation to Apple’s paste-command scanning protections added in macOS 26.4 for Terminal abuse; while newer macOS versions also warn about unidentified scripts, the attack can still succeed if users follow the prompts. Reported infrastructure tied to the campaign includes dryvecar.com, storage-fixes.squarespace.com, and cleanupmac.mssg.me.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
Analysis tied the campaign to infrastructure including dryvecar.com, storage-fixes.squarespace.com, and cleanupmac.mssg.me. The operation was described as targeting macOS users to steal browser credentials, saved passwords, cryptocurrency wallets, and other sensitive data.
Jamf researchers documented an active campaign delivering a variant of Atomic Stealer through Script Editor on macOS. They reported that the script fetched remote content with curl using disabled TLS certificate validation, executed it in memory, and ultimately downloaded a Mach-O payload.
After Apple’s Terminal-focused protections, attackers adapted their technique by using the applescript:// URL scheme to open Script Editor with a pre-filled malicious AppleScript. The lure used fake Apple-themed disk cleanup pages to socially engineer users into running the script.
Apple introduced protections in macOS 26.4 to scan pasted commands in Terminal and warn users about potentially suspicious activity. The new safeguards were intended to reduce abuse of Terminal-based social engineering techniques such as ClickFix-style attacks.
Netskope Threat Labs reported an active ClickFix campaign targeting macOS users in Asia’s finance sector with an AppleScript-based infostealer. The attack used fake CAPTCHA prompts to trick victims into pasting a malicious curl command, then displayed a persistent fake macOS password dialog to steal valid credentials and extensive browser, Keychain, extension, and cryptocurrency wallet data.
Guardio published research on a scam using fake 'Mac Storage Fix' lures promoted via Google Ads to target macOS users. The campaign appears to be an earlier stage of the social-engineering activity later associated with ClickFix-style macOS malware delivery.
Intego reported a new 'Matryoshka' ClickFix variant targeting macOS users through typosquatting infrastructure to deliver a stealer. The report indicates the campaign was already using ClickFix-style social engineering against Mac users before the later Google Ads and Script Editor activity documented by other researchers.
Microsoft Defender researchers reported that ClickFix had been targeting macOS users since at least January 2026, marking an expansion of the technique beyond Windows. The campaign used fake disk-space, error, and utility-install prompts on blogs and user-driven platforms to trick users into pasting Terminal commands that delivered Macsync, Shub Stealer, or Atomic macOS Stealer.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
9 references tracked. Mallory keeps watching after this page renders.
thecyberexpress.com
Open sourcetheregister.com
Open sourcehelpnetsecurity.com
Open sourcescworld.com
Open sourcecybersecuritynews.com
Open sourcethecyberexpress.com
Open sourcejamf.com
Open sourceguard.io
Open sourceintego.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.