ClickFix campaign uses fake macOS utilities lures to deliver infostealers
Threat actors are leveraging ClickFix-style social engineering tactics to distribute infostealers targeting macOS users through fake system utility lures. Attackers host malicious Terminal commands on blog sites and content platforms, disguised as troubleshooting advice for macOS issues. When executed, these commands download infostealers including Macsync, Shub Stealer, and AMOS, which exfiltrate browser credentials, cryptocurrency wallets, iCloud data, Keychain entries, and media files. The campaign has evolved to use Terminal-based script execution that bypasses Gatekeeper verification. Three distinct campaigns employ different tradecraft, with some replacing legitimate cryptocurrency wallet applications with trojanized versions and establishing persistence through LaunchAgents and LaunchDaemons that masquerade as legitimate services.
AI Analysis
Technical Summary
This campaign leverages ClickFix-style social engineering to distribute macOS infostealers through fake system utility lures. Attackers host malicious Terminal commands on blogs and content platforms, which when executed, download infostealers including Macsync, Shub Stealer, and AMOS. These malware families exfiltrate a wide range of sensitive user data such as browser credentials, cryptocurrency wallets, iCloud data, Keychain entries, and media files. The campaign uses Terminal-based script execution to bypass Gatekeeper verification, and persistence is established through LaunchAgents and LaunchDaemons masquerading as legitimate services. Some campaigns replace legitimate cryptocurrency wallet apps with trojanized versions. The threat actor behind this campaign is identified as PhantomRaven. There is no indication of known exploits in the wild or available patches.
Potential Impact
Successful execution of the malicious commands results in the installation of infostealers that exfiltrate sensitive user data including browser credentials, cryptocurrency wallets, iCloud data, Keychain entries, and media files. This can lead to credential theft, financial loss, privacy breaches, and unauthorized access to user accounts and devices. The campaign's ability to bypass Gatekeeper and establish persistence increases the risk of prolonged compromise on affected macOS systems.
Mitigation Recommendations
No official patch or fix is available for this campaign as it relies on social engineering and user execution of malicious commands. Users should avoid executing Terminal commands from untrusted sources and verify the authenticity of troubleshooting advice. Employ endpoint protection solutions capable of detecting malicious scripts and monitor for suspicious LaunchAgents and LaunchDaemons. Educate users about the risks of downloading and running unverified software or commands. Since this is not a vulnerability in macOS itself but a social engineering campaign, remediation focuses on user awareness and detection rather than patching.
Indicators of Compromise
- domain: console.info
- cve: CVE-2026-31431
- domain: pack.nppacks.com
- domain: hblnew.ecompk.com
- hash: 4bdb7aef96dc04c250cceefa222d7d1a
- hash: 83088e7cb00cf9fab74df2f64b7021b2deef6610
- hash: 0ce9b82d290004031b7cc49d724c00011811e1753a283a93a380a311360cfb66
- hash: 78937711bbc74542d304c7a7ea451465a2342438116fb37aa715ccf89b027d04
- hash: abe9ee9edfc44f7675400207a826c260b2f197d1f93e36010c35d627983e4294
- url: http://hblnew.ecompk.com/npm/local-rules
- url: http://pack.nppacks.com/mozbra.php
- url: http://pack.nppacks.com/npm/
- url: http://pack.nppacks.com/npm/graphql-js-client-transform
- url: http://pack.nppacks.com/npm/idle-style-xi
- url: http://pack.nppacks.com/npm/local-rules
- url: http://pack.nppacks.com/route.js
- url: http://pack.nppacks.com/token.php
- domain: ecompk.com
- domain: hblv2.ecompk.com
- domain: pkg.author.email
ClickFix campaign uses fake macOS utilities lures to deliver infostealers
Description
Threat actors are leveraging ClickFix-style social engineering tactics to distribute infostealers targeting macOS users through fake system utility lures. Attackers host malicious Terminal commands on blog sites and content platforms, disguised as troubleshooting advice for macOS issues. When executed, these commands download infostealers including Macsync, Shub Stealer, and AMOS, which exfiltrate browser credentials, cryptocurrency wallets, iCloud data, Keychain entries, and media files. The campaign has evolved to use Terminal-based script execution that bypasses Gatekeeper verification. Three distinct campaigns employ different tradecraft, with some replacing legitimate cryptocurrency wallet applications with trojanized versions and establishing persistence through LaunchAgents and LaunchDaemons that masquerade as legitimate services.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This campaign leverages ClickFix-style social engineering to distribute macOS infostealers through fake system utility lures. Attackers host malicious Terminal commands on blogs and content platforms, which when executed, download infostealers including Macsync, Shub Stealer, and AMOS. These malware families exfiltrate a wide range of sensitive user data such as browser credentials, cryptocurrency wallets, iCloud data, Keychain entries, and media files. The campaign uses Terminal-based script execution to bypass Gatekeeper verification, and persistence is established through LaunchAgents and LaunchDaemons masquerading as legitimate services. Some campaigns replace legitimate cryptocurrency wallet apps with trojanized versions. The threat actor behind this campaign is identified as PhantomRaven. There is no indication of known exploits in the wild or available patches.
Potential Impact
Successful execution of the malicious commands results in the installation of infostealers that exfiltrate sensitive user data including browser credentials, cryptocurrency wallets, iCloud data, Keychain entries, and media files. This can lead to credential theft, financial loss, privacy breaches, and unauthorized access to user accounts and devices. The campaign's ability to bypass Gatekeeper and establish persistence increases the risk of prolonged compromise on affected macOS systems.
Mitigation Recommendations
No official patch or fix is available for this campaign as it relies on social engineering and user execution of malicious commands. Users should avoid executing Terminal commands from untrusted sources and verify the authenticity of troubleshooting advice. Employ endpoint protection solutions capable of detecting malicious scripts and monitor for suspicious LaunchAgents and LaunchDaemons. Educate users about the risks of downloading and running unverified software or commands. Since this is not a vulnerability in macOS itself but a social engineering campaign, remediation focuses on user awareness and detection rather than patching.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.mend.io/blog/phantomraven-wave-5-new-undocumented-npm-supply-chain-campaign-targets-defi-cloud-and-ai-developers/"]
- Adversary
- PhantomRaven
- Pulse Id
- 69f8acdd6038448e350edbb9
- Threat Score
- null
Indicators of Compromise
Domain
| Value | Description | Copy |
|---|---|---|
domainconsole.info | — | |
domainpack.nppacks.com | — | |
domainhblnew.ecompk.com | — | |
domainecompk.com | — | |
domainhblv2.ecompk.com | — | |
domainpkg.author.email | — |
Cve
| Value | Description | Copy |
|---|---|---|
cveCVE-2026-31431 | — |
Hash
| Value | Description | Copy |
|---|---|---|
hash4bdb7aef96dc04c250cceefa222d7d1a | — | |
hash83088e7cb00cf9fab74df2f64b7021b2deef6610 | — | |
hash0ce9b82d290004031b7cc49d724c00011811e1753a283a93a380a311360cfb66 | — | |
hash78937711bbc74542d304c7a7ea451465a2342438116fb37aa715ccf89b027d04 | — | |
hashabe9ee9edfc44f7675400207a826c260b2f197d1f93e36010c35d627983e4294 | — |
Url
| Value | Description | Copy |
|---|---|---|
urlhttp://hblnew.ecompk.com/npm/local-rules | — | |
urlhttp://pack.nppacks.com/mozbra.php | — | |
urlhttp://pack.nppacks.com/npm/ | — | |
urlhttp://pack.nppacks.com/npm/graphql-js-client-transform | — | |
urlhttp://pack.nppacks.com/npm/idle-style-xi | — | |
urlhttp://pack.nppacks.com/npm/local-rules | — | |
urlhttp://pack.nppacks.com/route.js | — | |
urlhttp://pack.nppacks.com/token.php | — |
Threat ID: 69f8af02cbff5d86102ac390
Added to database: 5/4/2026, 2:36:50 PM
Last enriched: 6/10/2026, 8:41:06 AM
Last updated: 6/18/2026, 6:47:52 PM
Views: 353
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.