A routine-looking download can turn into a much bigger problem for Mac users.
Jamf Threat Labs found an AmnesiaStealer campaign reaching macOS through a fake software download and capable of keeping attackers connected to browser sessions after infection. Researchers say the added access can extend the intrusion beyond the malware’s initial data theft.
An attack begins with a user-run Terminal command, but its more unusual stage comes later, after AmnesiaStealer is already inside the system.
A fake download opens the door on macOS
Jamf Threat Labs traced the campaign to a counterfeit GitHub-style page offering a macOS download. Visitors are instructed to copy an encoded command into Terminal, using a ClickFix attack chain that relies on the target to execute the malicious instructions.
Running the command triggers a shell script that downloads and launches AmnesiaStealer. The malware also attempts to obtain the user’s login password as it prepares to collect information from the system.
Turning stolen data into browser access
AmnesiaStealer first collects information stored on the infected device. Jamf found it targeting browser data and the macOS Keychain, with Apple Notes and Telegram also in its sights.
Mac infostealers have pursued similar information before. FrigidStealer, for example, has targeted browser credentials and Apple Notes.
The malware can then download an optional component called stream_module. This can copy a Chromium browser profile and launch another browser instance outside the user’s view. Operators can see what appears in the browser and send keyboard or mouse input back to it.
Copied browser data can preserve an authenticated session. Services that still recognize an existing session may not immediately ask for another login. Stolen session cookies can create a similar problem, while remote browser control also allows an operator to interact with the session from the compromised system.
Must-read Apple coverage
- Nearly 7 in 10 iPhone Owners Plan iPhone 17 Upgrade
- Apple Prepares AI-Powered Siri Upgrade With Google Search Integration
- Apple’s Xcode 26 Beta Now Supports GPT-5 and Claude
- Apple’s Vision Pro Adoption Stalled As Content Released ‘Drip by Drip’
Work accounts raise the cost of a compromised device
If you use a Mac for work, treat a suspected AmnesiaStealer infection as more than a malware-removal job. Accounts already open in the browser may include company email or cloud services, depending on your role and access.
Take the affected device offline and contact your IT or security team if it is company-managed. Use a clean device to revoke active sessions and reset passwords for sensitive accounts. Review recent activity for anything you do not recognize.
If your role includes privileged or financial access, tell responders which services were open or recently used. A session tied to an administrative console or finance platform can carry permissions well beyond an ordinary user account.
Credential recovery should run alongside endpoint investigation. Unexpected Chromium processes or copied browser profiles can help establish whether the browser-control component was used. Recent threats such as ClickLock malware have already made credential theft a concern for Apple users, and AmnesiaStealer adds another form of access for defenders to account for after an infection.
Other News: WhatsApp is testing on-device AI scam alerts that flag suspicious messages from unknown senders without sending message content to the cloud.