Close Menu
Tech Nova Mindset – Empower Innovation and Forward Thinking

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    When AI goes rogue, its human overseers may be to blame

    September 17, 2026

    The Download: mice with part-human brains and climate tech innovators

    September 17, 2026

    Meet the innovators under 35 shaping climate tech

    September 17, 2026
    Facebook X (Twitter) Instagram
    Trending
    • When AI goes rogue, its human overseers may be to blame
    • The Download: mice with part-human brains and climate tech innovators
    • Meet the innovators under 35 shaping climate tech
    • Washington Won’t Be Regulating AI Anytime Soon
    • OpenAI Creates a New Framework to Disclose Bad AI Behavior
    • The Download: AI’s trillion-dollar gamble and OpenAI’s biology data bid
    • I Trained a Fly’s Brain to Generate WIRED Story Ideas
    • Building the materials foundation for AI
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    • Home
    • Gadgets
    • Reviews
    • Tech News
    • Future Tech
    • AI & Robotics
    • How-To Guides
    • More
      • Cybersecurity
      • Startups & Innovation
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    Home»Cybersecurity»New Infinity Stealer malware grabs macOS data via ClickFix lures
    Cybersecurity

    New Infinity Stealer malware grabs macOS data via ClickFix lures

    kirklandc008@gmail.comBy kirklandc008@gmail.comMarch 29, 2026No Comments3 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    New Infinity Stealer malware grabs macOS data via ClickFix lures
    Share
    Facebook Twitter LinkedIn Pinterest Email

    A new info-stealing malware named Infinity Stealer is targeting macOS systems with a Python payload packaged as an executable using the open-source Nuitka compiler.

    The attack uses the ClickFix technique, presenting a fake CAPTCHA that mimics Cloudflare’s human verification check to trick users into executing malicious code.

    Researchers at Malwarebytes say this is the first documented macOS campaign combining ClickFix delivery with a Python-based infostealer compiled using Nuitka.

    Because Nuitka produces a native binary by compiling the Python script into C code, the resulting executable is more resistant to static analysis.

    Compared to PyInstaller, which bundles Python with bytecode, it’s more evasive because it produces a real native binary with no obvious bytecode layer, making reverse engineering much harder.

    “The final payload is written in Python and compiled with Nuitka, producing a native macOS binary. That makes it harder to analyze and detect than typical Python-based malware,” Malwarebystes says.

    Attack chain

    The attack begins with a ClickFix lure on the domain update-check[.]com, posing as a human verification step from Cloudflare and asking the user to complete the challenge by pasting a base64-obfuscated curl command into the macOS Terminal, bypassing OS-level defenses.

    ClickFix step used in Infinity attacks
    Source: Malwarebytes

    The command decodes a Bash script that writes the stage-2 (Nuitka loader) to /tmp, then removes the quarantine flag, and executes it via ‘nohup.’ Finally, it passes the command-and-control (C2) and token via environment variables and then deletes itself and closes the Terminal window.

    The Nuitka loader is an 8.6 MB Mach-O binary that contains a 35MB zstd-compressed archive, containing the stage-3 (UpdateHelper.bin), which is the Infinity Stealer malware.

    The malware’s disassembly view
    Source: Malwarebytes

    Before starting to collect sensitive data, the malware performs anti-analysis checks to determine whether it is running in a virtualized/sandboxed environment.

    Malwarebytes’ analysis of the Python 3.11 payload uncovered that the info-stealer can take screenshots and harvest the following data:

    • Credentials from Chromium‑based browsers and Firefox
    • macOS Keychain entries
    • Cryptocurrency wallets
    • Plaintext secrets in developer files, such as .env

    All stolen data is exfiltrated via HTTP POST requests to the C2, and a Telegram notification is sent to the threat actors upon completion of the operation.

    Malwarebytes underlines that the appearance of malware like Infinity Stealer is proof that threats to macOS users are only getting more advanced and targeted.

    Users should never paste into Terminal commands they find online and don’t fully understand.

    Automated pentesting proves the path exists. BAS proves whether your controls stop it. Most teams run one without the other.

    This whitepaper maps six validation surfaces, shows where coverage ends, and provides practitioners with three diagnostic questions for any tool evaluation.

    Get Your Copy Now

    ClickFix data grabs Infinity lures macOS malware Stealer
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    kirklandc008@gmail.com
    • Website

    Related Posts

    The Download: AI’s trillion-dollar gamble and OpenAI’s biology data bid

    September 16, 2026

    AI models need more data about biology, and OpenAI is paying to create it

    September 16, 2026

    Meta Sued Over Training Data for Its AI and Face-Recognition Systems

    September 11, 2026
    Leave A Reply Cancel Reply

    Top Posts

    Nothing CEO says phone prices are going to keep going up

    June 12, 20267 Views

    The best VPN routers of 2026: Expert tested and reviewed

    June 14, 20263 Views

    Google DeepMind Plans to Track AGI Progress With These 10 Traits of General Intelligence

    March 21, 20263 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Recent Posts
    • When AI goes rogue, its human overseers may be to blame
    • The Download: mice with part-human brains and climate tech innovators
    • Meet the innovators under 35 shaping climate tech
    • Washington Won’t Be Regulating AI Anytime Soon
    • OpenAI Creates a New Framework to Disclose Bad AI Behavior

    When AI goes rogue, its human overseers may be to blame

    September 17, 2026

    The Download: mice with part-human brains and climate tech innovators

    September 17, 2026

    Meet the innovators under 35 shaping climate tech

    September 17, 2026

    Washington Won’t Be Regulating AI Anytime Soon

    September 17, 2026
    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    © 2026 TechNovaMindset. Designed by By Pro.

    Type above and press Enter to search. Press Esc to cancel.