Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Fortinet Patches Critical Auth Bypass in FortiWeb, FortiManager, FortiClient
August 13, 2026
AmnesiaStealer macOS Malware Hijacks Browser Sessions via Fake GitHub Lure
August 13, 2026
Beacon CRM confirms full database theft after AWS access key breach
August 13, 2026
Home/CyberSecurity News/AmnesiaStealer macOS Malware Hijacks Browser Sessions via Fake GitHub Lure
CyberSecurity News

AmnesiaStealer macOS Malware Hijacks Browser Sessions via Fake GitHub Lure

Key Takeaways A new macOS infostealer, AmnesiaStealer, is actively targeting Mac users through a sophisticated fake GitHub download page. The malware leverages a social engineering technique called...

Marcus Rodriguez
Marcus Rodriguez
August 13, 2026 4 Min Read
2 0

Key Takeaways

  • A new macOS infostealer, AmnesiaStealer, is actively targeting Mac users through a sophisticated fake GitHub download page.
  • The malware leverages a social engineering technique called “ClickFix,” prompting users to execute a malicious Terminal command.
  • AmnesiaStealer steals sensitive data, including login credentials, browser sessions, and other personal information.
  • Its most dangerous feature allows attackers to remotely control a victim’s live browser session, enabling access to banking, email, and social media.
  • While some of the malware’s evasion tactics are outdated, its core data theft capabilities remain effective, particularly against users with broad system permissions.

New macOS Infostealer AmnesiaStealer Hijacks Browser Sessions via Elaborate GitHub Impersonation

A novel macOS information stealer, dubbed AmnesiaStealer, has been identified exploiting a highly convincing counterfeit GitHub download page to compromise Mac systems. This sophisticated malware campaign deceives users into executing a malicious Terminal command, leading to the silent installation of malware and, critically, providing attackers with real-time, covert control over the victim’s browser sessions.

Table Of Content

  • Key Takeaways
  • New macOS Infostealer AmnesiaStealer Hijacks Browser Sessions via Elaborate GitHub Impersonation
  • The Deceptive GitHub Lure
  • Infection Chain and Data Exfiltration
  • Live Browser Session Control: The Most Severe Threat
  • What You Should Do

The Deceptive GitHub Lure

Researchers at Jamf Threat Labs uncovered this threat after observing a fraudulent website, github.aoitour[.]com, meticulously designed to mimic GitHub’s official interface. The fake site replicated GitHub’s dark theme, the iconic Octocat logo, and even displayed a “Verified Publisher” badge to enhance its legitimacy.

Instead of offering a legitimate software download, the deceptive page presented a “Terminal installation” prompt. This prompt included a one-click copy button and detailed instructions, guiding visitors to open their Terminal application, paste the provided command, press Return, and subsequently enter their device password.

This social engineering tactic, known as ClickFix, has been previously employed in distributing other macOS malware families, such as Atomic (AMOS) and MacSync. This indicates a concerning trend where cybercriminal groups are reusing successful deceptive templates across various malicious campaigns.

Infection Chain and Data Exfiltration

Upon a victim pasting and executing the malicious Terminal command, a hidden shell script is triggered. This script surreptitiously downloads a password-protected ZIP archive, extracts a disguised binary into the /tmp directory, removes Apple’s quarantine flag, and then launches the malicious payload before erasing its own traces.

The subsequent stage involves a Rust-based infostealer. This component first profiles the compromised machine, then displays a fake native “Installer” password prompt to trick the user into revealing their login credentials. These stolen credentials are then used to unlock and exfiltrate data from the macOS keychain, Apple Notes, Telegram sessions, browser data, and various documents.

The malware derives its name from the “Amnesia Panel,” its command-and-control backend, with its embedded configuration secured by the key 4mn3s1a_2o26!xK.

Live Browser Session Control: The Most Severe Threat

The most alarming capability of AmnesiaStealer resides in its third component, named stream_module. This module is retrieved only upon specific instructions from the attacker’s control panel. Once deployed, it clones the victim’s browser profile, initiates it in headless mode, and establishes a connection with the Chrome DevTools Protocol.

This sophisticated technique grants the attacker a live screencast of the victim’s browser session and complete control over mouse, keyboard, and navigation. As a result, attackers can fully operate the victim’s logged-in browser sessions, including access to email, banking, and social media accounts, all without any visible indication to the victim on their own screen, as reads the Jamf Threat Labs report.

Interestingly, some of the malware’s attempts to circumvent Apple’s privacy protections rely on techniques that Apple patched years ago, including an APFS snapshot bypass from 2020. While these older evasion methods largely fail on modern macOS versions like macOS 26, with the malware’s own debug logs recording the failures, its primary functions of credential and browser-session theft remain highly effective, particularly against advanced users who might have previously granted broader system permissions.

AmnesiaStealer exemplifies a growing trend in cyberattacks where threat actors combine highly believable phishing pages with staged, remotely triggered payloads, moving beyond reliance on a single, static malware file.

What You Should Do

  • Never Paste Unknown Commands: The most critical defense is to refrain from pasting any unknown commands into the Terminal, especially those originating from unsolicited download prompts or unfamiliar websites.
  • Keep macOS Updated: Ensure your macOS operating system is always running the latest version to benefit from Apple’s security patches and enhancements.
  • Utilize Endpoint Protection: Deploy and maintain robust browser and endpoint threat protection solutions on all macOS devices.
  • Scrutinize Password Prompts: Treat any password prompt associated with a “software installer” with extreme suspicion. Always verify the legitimacy of the installer and the source before entering credentials.
  • Exercise Caution with Downloads: Only download software from official and trusted sources. Be wary of third-party sites impersonating legitimate platforms.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackMalwarePatchphishingSecurityThreat

Share Article

Marcus Rodriguez

Marcus Rodriguez

Marcus is a security researcher and investigative journalist with expertise in vulnerability research, bug bounties, and cloud security. Since 2017, Marcus has been breaking stories on critical vulnerabilities affecting major platforms. His investigative work has led to the disclosure of numerous security flaws and improved defenses across the industry. Marcus is an active participant in bug bounty programs and has been recognized for responsible disclosure practices. He holds multiple security certifications and regularly speaks at industry events.

Previous Post

Beacon CRM confirms full database theft after AWS access key breach

Next Post

Fortinet Patches Critical Auth Bypass in FortiWeb, FortiManager, FortiClient

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
North Korean IT Workers Impersonate Employees Using Forged IDs
August 13, 2026
CISA Warns of Critical Windows Ancillary Function Driver Zero-Day Exploited in Attacks
August 13, 2026
Likho Stealer’s New Toolkit Steals Telegram Sessions and Records Conversations
August 13, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us