ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets

ClickFix-style attacks are deploying a Go-based macOS stealer that drains cryptocurrency wallets and steals browser passwords, iCloud Keychain data, and cached credentials. The infection chain uses a shell script to profile the host before fetching a CPU-compatible malware payload.

ClickFix attacks are delivering a Go-based macOS stealer that can drain cryptocurrency wallets, steal browser passwords, Apple iCloud Keychain data, and cached credentials. The infection chain uses a shell script to profile the victim's host, then fetches a macOS malware payload tailored to the computer's CPU architecture. The malware targets digital assets and sensitive credentials stored on Mac systems.