A DPRK-linked campaign is targeting macOS users with fake full-screen update prompts delivered through malvertising or injected scripts, tricking victims into pasting a clipboard-loaded command into Terminal. The command launches a multi-stage infection chain tied by tradecraft to UNC5342 and Contagious Interview, installing Node.js and an obfuscated backdoor that retrieves command-and-control settings from Ethereum smart contracts through public RPC endpoints. By using EtherHiding instead of fixed infrastructure, the operators make their C2 configuration more resilient to disruption and takedown.
After execution, the malware deploys an infostealer aimed at 157 cryptocurrency wallets, browser secrets, and developer credentials, and installs a malicious Chrome extension masquerading as Google Drive Offline to maintain browser-level access. AllSecure linked the malware, infrastructure, extension, and on-chain funding flows to a broader crypto-theft operation, tracking 464.80 ETH—about $890,000—into attacker treasury infrastructure between late May and July 2026, with laundering paths leading toward tagged phishing-related sink wallets. Defenders are advised to treat any host where the pasted command was executed as fully compromised, isolate it immediately, reset credentials from a clean device, and move cryptocurrency assets to a clean wallet.

Pull IOCs and campaign context straight into your stack.
4 events from the most recent confirmed update back to the earliest known activity.
Huntress identified the MacSync macOS information stealer during a mid-July intrusion investigation. The campaign used sponsored Google results and a fake Claude installation guide to trick victims into pasting a malicious Terminal command, leading to credential theft, wallet targeting, persistence, and RAT deployment.
AllSecure tracked 464.80 ETH, valued at about $890,000, flowing into attacker treasury infrastructure. The tracked inflows occurred between late May and July 2026 and were cited as part of the operation's wallet and laundering trail.
AllSecure published a report linking the campaign's infrastructure, malware, browser extension, and on-chain funding flows to a DPRK-linked crypto-theft operation aligned with UNC5342 and Contagious Interview tradecraft. The report also described disposable wallet deployment patterns, exchange-funded operating capital, and laundering paths into tagged sink wallets.
During a malvertising investigation, AllSecure identified a macOS-focused campaign that used fake update screens to trick users into pasting a malicious command into Terminal. The infection chain installed a Node.js backdoor that retrieved command-and-control configuration from Ethereum smart contracts and deployed tooling to steal wallet data, browser secrets, and developer credentials.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 42 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
4 references tracked. Mallory keeps watching after this page renders.
cryptika.com
Open sourcecybersecuritynews.com
Open sourcebsky.app
Open sourceallsecure.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.