ClickFix campaign uses fake macOS utilities lures to deliver infostealers
The ClickFix campaign targets macOS users by using fake system utility lures to distribute infostealers. Attackers host malicious Terminal commands disguised as troubleshooting advice on blogs and content platforms. Executing these commands downloads infostealers such as Macsync, Shub Stealer, and AMOS, which steal browser credentials, cryptocurrency wallets, iCloud data, Keychain entries, and media files. The campaign bypasses Gatekeeper verification by using Terminal-based script execution and employs persistence mechanisms like LaunchAgents and LaunchDaemons that mimic legitimate services. Some campaigns replace legitimate cryptocurrency wallet applications with trojanized versions.
AI Analysis
Technical Summary
This campaign leverages social engineering via fake macOS utility lures to deliver multiple infostealers targeting sensitive user data. Malicious Terminal commands hosted on public platforms are disguised as legitimate troubleshooting instructions. When run, these commands download and execute infostealers including Macsync, Shub Stealer, and AMOS. These malware variants exfiltrate a range of sensitive data such as browser credentials, cryptocurrency wallets, iCloud data, Keychain entries, and media files. The campaign uses Terminal-based script execution techniques that evade macOS Gatekeeper protections. Persistence is established through LaunchAgents and LaunchDaemons masquerading as legitimate services. Some variants trojanize cryptocurrency wallet applications to maintain access and facilitate credential theft. The adversary behind this campaign is identified as PhantomRaven.
Potential Impact
Successful execution of the malicious commands results in the installation of infostealers that exfiltrate highly sensitive user data including browser credentials, cryptocurrency wallets, iCloud data, Keychain entries, and media files. This can lead to credential theft, financial loss, privacy breaches, and unauthorized access to user accounts and assets. The campaign’s ability to bypass Gatekeeper and establish persistence increases the risk of prolonged compromise on affected macOS systems.
Mitigation Recommendations
No official patch or fix is indicated for this campaign. Mitigation focuses on user awareness to avoid executing untrusted Terminal commands, especially those sourced from unverified blogs or content platforms. Users should verify the authenticity of troubleshooting advice before execution. Employing endpoint security solutions that detect and block known infostealers and monitoring for suspicious persistence mechanisms such as unauthorized LaunchAgents and LaunchDaemons is recommended. Gatekeeper bypass techniques highlight the need for layered security controls beyond default macOS protections.
Indicators of Compromise
- domain: console.info
- cve: CVE-2026-31431
- domain: pack.nppacks.com
- domain: hblnew.ecompk.com
- hash: 4bdb7aef96dc04c250cceefa222d7d1a
- hash: 83088e7cb00cf9fab74df2f64b7021b2deef6610
- hash: 0ce9b82d290004031b7cc49d724c00011811e1753a283a93a380a311360cfb66
- hash: 78937711bbc74542d304c7a7ea451465a2342438116fb37aa715ccf89b027d04
- hash: abe9ee9edfc44f7675400207a826c260b2f197d1f93e36010c35d627983e4294
- url: http://hblnew.ecompk.com/npm/local-rules
- url: http://pack.nppacks.com/mozbra.php
- url: http://pack.nppacks.com/npm/
- url: http://pack.nppacks.com/npm/graphql-js-client-transform
- url: http://pack.nppacks.com/npm/idle-style-xi
- url: http://pack.nppacks.com/npm/local-rules
- url: http://pack.nppacks.com/route.js
- url: http://pack.nppacks.com/token.php
- domain: ecompk.com
- domain: hblv2.ecompk.com
- domain: pkg.author.email
ClickFix campaign uses fake macOS utilities lures to deliver infostealers
Description
The ClickFix campaign targets macOS users by using fake system utility lures to distribute infostealers. Attackers host malicious Terminal commands disguised as troubleshooting advice on blogs and content platforms. Executing these commands downloads infostealers such as Macsync, Shub Stealer, and AMOS, which steal browser credentials, cryptocurrency wallets, iCloud data, Keychain entries, and media files. The campaign bypasses Gatekeeper verification by using Terminal-based script execution and employs persistence mechanisms like LaunchAgents and LaunchDaemons that mimic legitimate services. Some campaigns replace legitimate cryptocurrency wallet applications with trojanized versions.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This campaign leverages social engineering via fake macOS utility lures to deliver multiple infostealers targeting sensitive user data. Malicious Terminal commands hosted on public platforms are disguised as legitimate troubleshooting instructions. When run, these commands download and execute infostealers including Macsync, Shub Stealer, and AMOS. These malware variants exfiltrate a range of sensitive data such as browser credentials, cryptocurrency wallets, iCloud data, Keychain entries, and media files. The campaign uses Terminal-based script execution techniques that evade macOS Gatekeeper protections. Persistence is established through LaunchAgents and LaunchDaemons masquerading as legitimate services. Some variants trojanize cryptocurrency wallet applications to maintain access and facilitate credential theft. The adversary behind this campaign is identified as PhantomRaven.
Potential Impact
Successful execution of the malicious commands results in the installation of infostealers that exfiltrate highly sensitive user data including browser credentials, cryptocurrency wallets, iCloud data, Keychain entries, and media files. This can lead to credential theft, financial loss, privacy breaches, and unauthorized access to user accounts and assets. The campaign’s ability to bypass Gatekeeper and establish persistence increases the risk of prolonged compromise on affected macOS systems.
Mitigation Recommendations
No official patch or fix is indicated for this campaign. Mitigation focuses on user awareness to avoid executing untrusted Terminal commands, especially those sourced from unverified blogs or content platforms. Users should verify the authenticity of troubleshooting advice before execution. Employing endpoint security solutions that detect and block known infostealers and monitoring for suspicious persistence mechanisms such as unauthorized LaunchAgents and LaunchDaemons is recommended. Gatekeeper bypass techniques highlight the need for layered security controls beyond default macOS protections.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.mend.io/blog/phantomraven-wave-5-new-undocumented-npm-supply-chain-campaign-targets-defi-cloud-and-ai-developers/"]
- Adversary
- PhantomRaven
- Pulse Id
- 69f8acdd6038448e350edbb9
- Threat Score
- null
Indicators of Compromise
Domain
| Value | Description | Copy |
|---|---|---|
domainconsole.info | — | |
domainpack.nppacks.com | — | |
domainhblnew.ecompk.com | — | |
domainecompk.com | — | |
domainhblv2.ecompk.com | — | |
domainpkg.author.email | — |
Cve
| Value | Description | Copy |
|---|---|---|
cveCVE-2026-31431 | — |
Hash
| Value | Description | Copy |
|---|---|---|
hash4bdb7aef96dc04c250cceefa222d7d1a | — | |
hash83088e7cb00cf9fab74df2f64b7021b2deef6610 | — | |
hash0ce9b82d290004031b7cc49d724c00011811e1753a283a93a380a311360cfb66 | — | |
hash78937711bbc74542d304c7a7ea451465a2342438116fb37aa715ccf89b027d04 | — | |
hashabe9ee9edfc44f7675400207a826c260b2f197d1f93e36010c35d627983e4294 | — |
Url
| Value | Description | Copy |
|---|---|---|
urlhttp://hblnew.ecompk.com/npm/local-rules | — | |
urlhttp://pack.nppacks.com/mozbra.php | — | |
urlhttp://pack.nppacks.com/npm/ | — | |
urlhttp://pack.nppacks.com/npm/graphql-js-client-transform | — | |
urlhttp://pack.nppacks.com/npm/idle-style-xi | — | |
urlhttp://pack.nppacks.com/npm/local-rules | — | |
urlhttp://pack.nppacks.com/route.js | — | |
urlhttp://pack.nppacks.com/token.php | — |
Threat ID: 69f8af02cbff5d86102ac390
Added to database: 05/04/2026, 14:36:50 UTC
Last enriched: 06/19/2026, 19:27:35 UTC
Last updated: 08/02/2026, 02:02:48 UTC
Views: 604
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.