Close Menu
Tech Nova Mindset – Empower Innovation and Forward Thinking

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Adopt This Data Center Plushie and Hear Its Piercing Scream

    September 19, 2026

    If the AI Industry Followed Its Own Research, It Might Have Paused Already

    September 19, 2026

    Single-Phase Direct Liquid Cooling Is Proven for the Next Decade of Ultra-Dense Compute

    September 19, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Adopt This Data Center Plushie and Hear Its Piercing Scream
    • If the AI Industry Followed Its Own Research, It Might Have Paused Already
    • Single-Phase Direct Liquid Cooling Is Proven for the Next Decade of Ultra-Dense Compute
    • Virtual Biotech Company Puts 37,000 AI Agents to Work on Drug Discovery
    • Here’s How an AI Slowdown Could Actually Be Enforced
    • Could AI really kill us all? Your questions, answered.
    • Turning Tech Talent Into Leadership Legacy
    • AI PACs Have Dumped Nearly $1 Million Into an Obscure Senate Race
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    • Home
    • Gadgets
    • Reviews
    • Tech News
    • Future Tech
    • AI & Robotics
    • How-To Guides
    • More
      • Cybersecurity
      • Startups & Innovation
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    Home»Cybersecurity»Cloudflare-Themed ClickFix Attack Drops Infiniti Stealer on Macs
    Cybersecurity

    Cloudflare-Themed ClickFix Attack Drops Infiniti Stealer on Macs

    kirklandc008@gmail.comBy kirklandc008@gmail.comMarch 28, 2026No Comments2 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    macOS malware
    Share
    Facebook Twitter LinkedIn Pinterest Email

    macOS users are targeted in a fresh ClickFix campaign that uses a Cloudflare-themed verification page to deliver a Python-based information stealer, Malwarebytes reports.

    The attack starts with a fake CAPTCHA page that serves a legitimate-looking Cloudflare human verification page asking visitors to paste and execute a command in Terminal.

    Referred to as ClickFix, the technique relies on social engineering to trick users into executing malicious commands on their devices and has been widely used in attacks since August 2024, mainly against Windows users.

    For more than half a year, however, attacks tailored for macOS have become increasingly convincing, and the variant observed by Malwarebytes is no different.

    The fake verification page provides macOS users with specific instructions to open the Terminal and paste and execute a fake verification command that triggers malware execution.

    Once the victim runs the command, a Bash script is fetched from a remote server. The script decodes an embedded payload, writes the second stage binary to a temporary folder, removes its quarantine flag, and executes it.

    Advertisement. Scroll to continue reading.

    The script also passes command-and-control (C&C) server and authentication tokens as environment variables, deletes itself, and closes the Terminal.

    The binary dropped by the script is a loader compiled using Nuitka. The compiler transforms Python code into a native binary, making static analysis more difficult.

    At runtime, the loader decompresses embedded data and launches the final payload, identified as the Infiniti Stealer malware.

    The Python-based information stealer targets browser credentials, Keychain information, cryptocurrency wallets, secrets stored in developer files, and screenshots captured during execution.

    The data is sent to the C&C via HTTP POST requests. Once the operation has been completed, the malware sends a notification to a Telegram channel and queues captured credentials to be cracked on the server.

    For evasion, Infiniti Stealer relies on randomized execution delay and checks if the system is a known analysis environment.

    “Infiniti Stealer shows how techniques that worked on Windows—like ClickFix—are now being adapted to target Mac users. It also uses newer techniques, like compiling Python into native apps, which makes the malware harder to detect and analyze. If this approach proves effective, we may see more attacks like this,” Malwarebytes notes.

    Related: Over 100 GitHub Repositories Distributing BoryptGrab Stealer

    Related: ‘SolyxImmortal’ Information Stealer Emerges

    Related: North Korean Hackers Target macOS Developers via Malicious VS Code Projects

    Related: MacSync macOS Malware Distributed via Signed Swift Application

    attack ClickFix CloudflareThemed drops Infiniti Macs Stealer
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    kirklandc008@gmail.com
    • Website

    Related Posts

    Physical AI Safety Under Attack From Silent Backdoors

    September 16, 2026

    A fundamental flaw leaves LLMs strikingly vulnerable to attack

    July 31, 2026

    OpenAI called the Hugging Face attack unprecedented. But we’ve been here before. 

    July 27, 2026
    Leave A Reply Cancel Reply

    Top Posts

    Nothing CEO says phone prices are going to keep going up

    June 12, 20267 Views

    The best VPN routers of 2026: Expert tested and reviewed

    June 14, 20263 Views

    Google DeepMind Plans to Track AGI Progress With These 10 Traits of General Intelligence

    March 21, 20263 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Recent Posts
    • Adopt This Data Center Plushie and Hear Its Piercing Scream
    • If the AI Industry Followed Its Own Research, It Might Have Paused Already
    • Single-Phase Direct Liquid Cooling Is Proven for the Next Decade of Ultra-Dense Compute
    • Virtual Biotech Company Puts 37,000 AI Agents to Work on Drug Discovery
    • Here’s How an AI Slowdown Could Actually Be Enforced

    Adopt This Data Center Plushie and Hear Its Piercing Scream

    September 19, 2026

    If the AI Industry Followed Its Own Research, It Might Have Paused Already

    September 19, 2026

    Single-Phase Direct Liquid Cooling Is Proven for the Next Decade of Ultra-Dense Compute

    September 19, 2026

    Virtual Biotech Company Puts 37,000 AI Agents to Work on Drug Discovery

    September 18, 2026
    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    © 2026 TechNovaMindset. Designed by By Pro.

    Type above and press Enter to search. Press Esc to cancel.