Fake AI Installers Deliver Password Stealers to macOS Users
Key Takeaways Cybercriminals are distributing MacSync, a potent macOS password stealer, through fake installers for popular AI tools like Claude and ChatGPT. The attack primarily leverages social...
Key Takeaways
- Cybercriminals are distributing MacSync, a potent macOS password stealer, through fake installers for popular AI tools like Claude and ChatGPT.
- The attack primarily leverages social engineering, tricking users into executing malicious commands in Terminal rather than exploiting software vulnerabilities.
- MacSync is a “malware-as-a-service” offering, indicating a structured and scalable operation by its developers.
- The malware is designed to exfiltrate a wide range of sensitive data, including browser credentials, session cookies, SSH keys, and cryptocurrency wallet information.
- Victims face significant risks, including account compromise and persistent system surveillance, necessitating comprehensive remediation beyond simple password changes.
macOS users seeking to download AI applications are falling victim to a sophisticated malware campaign that employs deceptive installers for popular tools like Claude and ChatGPT. This operation, which utilizes sponsored search results to lure targets, delivers “MacSync,” a potent password-stealing malware.
Table Of Content
Unlike attacks that exploit technical vulnerabilities, this campaign relies heavily on social engineering. Users are typically directed to fraudulent websites that mimic legitimate AI service providers. These sites then present a seemingly benign error message, claiming a download, connection, or verification has failed. Victims are subsequently instructed to copy and paste a specific command into their Terminal application, unknowingly granting attackers a direct entry point into their devices.
MacSync operates as a malware-as-a-service (MaaS), signifying that its creators provide the malicious tool and supporting infrastructure to other cybercriminal entities. Researchers noted the emergence of this threat in 2025, according to a report.
The danger posed by MacSync extends far beyond the theft of a single password. This malware is engineered to harvest a comprehensive array of sensitive data, including browser login credentials, active session cookies, Mac Keychain data, SSH keys, cloud service credentials, messaging application sessions, and cryptocurrency wallet information. SEQRITE said in a report that the malware can also establish persistent access, leaving both personal accounts and corporate systems vulnerable to long-term compromise.
Deceptive Tactics: Fake Installers and ClickFix Lures
The initial phase of the attack frequently begins when a user searches for a desktop AI application. Threat actors manipulate search engine results, often through paid placements, to direct unsuspecting individuals to spoofed websites. These sites are meticulously designed to impersonate legitimate services such as Claude AI, ChatGPT, or various developer tools. Instead of offering a standard application package, these fraudulent pages display a “ClickFix” prompt.
These ClickFix prompts are varied, often alleging issues like a broken WebSockets connection, a pending CAPTCHA, or an audio problem requiring attention. The critical step involves tricking users into pasting a seemingly helpful command into their Terminal application, thereby initiating the infection process themselves. This method is highly effective because it bypasses many traditional security warnings, as the user actively participates in the malware delivery.
This broader pattern has been observed in previous macOS ClickFix credential theft campaigns. Once executed, a shell script initiates a background process and deploys the native MacSync stager. This stager then detaches from the Terminal session, operates silently in the background, and fetches further instructions from attacker-controlled infrastructure. This modular design allows operators to dynamically update their payloads.
Stealthy Data Exfiltration
MacSync’s stealth capabilities are noteworthy. It downloads an AppleScript directly into memory and executes it using a built-in macOS automation utility, avoiding the creation of easily detectable script files. This script can then generate a convincing, system-like password prompt to collect credentials and other sensitive information from the compromised Mac.
The malware meticulously packages stolen data, including browser vaults and cryptocurrency wallet databases, transmitting it in fixed-size chunks to its command-and-control (C2) servers. Should a transfer fail, MacSync employs a retry mechanism with increasing delays. Upon successful exfiltration, it cleans up temporary files, minimizing forensic evidence for both users and incident response teams.
Furthermore, MacSync can establish persistence by deploying a remote-access component that utilizes macOS’s launch mechanisms to activate after login. An auxiliary program may also request screen-recording permissions, providing attackers with the ability to monitor user activity or capture sensitive visual content. This multi-stage approach allows the campaign to escalate from an initial fake installer to comprehensive account takeover and persistent surveillance.
These findings align with a broader trend of AI-themed malware delivery. In a related incident, a weaponized ChatGPT download site utilized sponsored advertisements and misleading download options to target both Mac and Windows users. The use of familiar branding effectively lowers user suspicion, particularly when individuals are actively seeking new tools or quick solutions to perceived problems.
What You Should Do
- Verify Software Sources: Always download software directly from the official vendor’s website. Avoid using sponsored search results or third-party download sites. Type the URL directly into your browser or use trusted bookmarks.
- Exercise Caution with Terminal Commands: Never copy and paste commands from web pages, chats, advertisements, or unsolicited support messages into your Terminal unless you fully understand the command’s function and have independently verified its legitimacy from a trusted source.
- Monitor for Suspicious Activity: Regularly check your Mac for unfamiliar launch items, unexpected permission requests (especially for screen recording), and unusual network activity.
- Implement Strong Authentication: Use strong, unique passwords for all accounts and enable multi-factor authentication (MFA) wherever possible.
- Incident Response: If you suspect an infection, simply resetting passwords may be insufficient. Immediately revoke active sessions for all compromised accounts, rotate any exposed API keys or credentials, and have the affected device thoroughly examined by a cybersecurity professional to eliminate persistence mechanisms.
- Block Known Indicators: Security teams should proactively block the listed command-and-control infrastructure and investigate any unexpected command-line activity originating from web browsers.
Indicators of Compromise (IoCs):-<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/8d0fe1b0-455e-49c0-a32e-2d625faf3ff0/Hackers-Use-Fake-Claude-and-ChatGPT-Installers-to-Infect-Mac-Users-With-Password-Stealing-Malware.pdf?AWSAccessKeyId=ASIA2F3EMEYEUMAEYPKM&Signature=0tYIr03kNIt
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.