GoPlus: A malicious program uses ClickFix to attack Mac users and steal crypto wallets
Foresight News reported that GoPlus has issued a security warning: the malicious program Infiniti Stealer is currently targeting the crypto wallets of Mac users. This program employs social engineering tactics known as “ClickFix,” luring users to execute malicious commands in the terminal by impersonating a Cloudflare CAPTCHA page.
After executing the command, the attack chain removes macOS’s quarantine attribute and runs its payload in the background. The final payload is a Python theft program compiled into a native binary via Nuitka, which offers strong detection evasion capabilities. Infiniti Stealer collects browser credentials, macOS Keychain, crypto wallets, and developer keys (such as .env files), and features sandbox detection and delayed execution.
GoPlus advises users to follow the principles of “do not click, do not install, do not sign, do not transfer,” check for persistent files in the /tmp and ~/Library/LaunchAgents/ directories, and reset credentials promptly.
Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.
You may also like
Mizuho lowers target price for a certain exchange to $43
Bank of America lowers CSX Transportation price target to $55
BTC Price Slides Toward $80K, AVAX Defies Market Correction: Weekend Watch
Samsung Electronics will double the production of HBM4 and HBM4E next year
