AmnesiaStealer macOS Malware Hijacks Browser Sessions via Fake GitHub Lure
Cybersecurity NewsArchived Aug 13, 2026✓ Full text saved
A newly identified macOS infostealer called AmnesiaStealer is spreading via a convincing fake GitHub download page, tricking Mac users into pasting a malicious Terminal command that silently installs malware and can later grant attackers live, hidden control of the victim’s browser session. Security researchers at Jamf Threat Labs discovered the campaign after spotting a counterfeit […] The post AmnesiaStealer macOS Malware Hijacks Browser Sessions via Fake GitHub Lure appeared first on Cyber Se
Full text archived locally
✦ AI Summary· Claude Sonnet
HomeCyber Attack News
AmnesiaStealer macOS Malware Hijacks Browser Sessions via Fake GitHub Lure
By Guru Baran
August 13, 2026
AmnesiaStealer macOS Malware Hijacks Browser Sessions via Fake GitHub Lure
A newly identified macOS infostealer called AmnesiaStealer is spreading via a convincing fake GitHub download page, tricking Mac users into pasting a malicious Terminal command that silently installs malware and can later grant attackers live, hidden control of the victim’s browser session.
Security researchers at Jamf Threat Labs discovered the campaign after spotting a counterfeit site at github.aoitour[.]com that near-perfectly copies GitHub’s dark theme, Octocat logo, and “Verified Publisher” badge.
Instead of offering a real download, the page displays a “Terminal installation” box with a one-click copy button and step-by-step instructions telling visitors to open Terminal, paste the command, press Return, and enter their device password.
This social-engineering technique, known as ClickFix, has also been used to spread other Mac malware families like Atomic (AMOS) and MacSync, showing that criminal groups are reusing the same deceptive template across campaigns.
Counterfeit GitHub ClickFix Terminal Lure (Image Source: .jamf.com)
Once a victim pastes the command, a hidden shell script quietly downloads a password-protected ZIP archive, extracts a disguised binary into the /tmp folder, strips Apple’s quarantine flag, and launches the payload before deleting its own tracks.
This is followed by a Rust-based infostealer that profiles the machine, displays a fake native “Installer” password prompt to capture the login credential, and uses it to unlock the keychain, Apple Notes, Telegram sessions, browser data, and documents.
The malware is named after the “Amnesia Panel” backend it communicates with, and its embedded configuration is unlocked with the key 4mn3s1a_2o26!xK.
Spoofed macOS System Password Prompt (Image Source: .jamf.com)
The most concerning capability arrives in a third component called stream_module. Fetched only on command from the attacker’s panel, this stage clones the victim’s browser profile, launches it in headless mode, and connects to the Chrome DevTools Protocol.
This gives the attacker a live screencast of the session along with full mouse, keyboard, and navigation control, effectively letting them operate the victim’s logged-in browser sessions, email, banking, and social media without the victim ever seeing anything change on their own screen, reads the Jamf Threat Labs report shared with Cyber Security News.
Interestingly, several of the malware’s attempts to sidestep Apple’s privacy protections rely on techniques Apple patched years ago, including a 2020 APFS snapshot bypass.
On modern macOS versions like macOS 26, these attempts largely fail, and the malware’s own debug logs record the failures. However, its core credential and browser-session theft still works effectively, especially against advanced users who may already have granted broader system permissions.
AmnesiaStealer illustrates a growing trend where attackers combine believable phishing pages with staged, remotely triggered payloads rather than a single static malware file.
Because the initial infection relies entirely on tricking a user into running a Terminal command, the most effective defense is simple: never paste unknown commands into Terminal, especially ones sourced from unsolicited download prompts.
Keeping macOS updated, enabling browser and endpoint threat protection, and treating any password prompt tied to a “software installer” with suspicion are essential precautions as this campaign continues to evolve.
Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.
Tags
cyber security
cyber security news
malware
Copy URL
Linkedin
Twitter
ReddIt
Telegram
Guru Baranhttps://cybersecuritynews.com
Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.
Cyber Security Guide
Top 10 Malware Threats of the Week – AsyncRAT, Remcos, and Xworm Lead the Surge
Three PhaaS Kits Targeting US Organizations to Steal M65 Logins by Bypassing MFA
How Top SOCs Detect and Stop AI Phishing that Beats Email Gateways
Top 10 Phishing Kits Used by Hackers to Launch Cyberattacks (July 20-26, 2026)
An SOC Story of Why Fast Answers Beat Perfect Answers in Cyber Incident Response
Latest Cyber News
Cyber Security
Trezor ShipMonk Data Breach Exposes Personal Data of Over 13,000 Hardware Wallet Customers
Cyber Security News
North Korean IT Workers Use AI-Forged IDs and Remote Desktops to Become Trusted Employees
Cyber Security News
CISA Warns of Windows Ancillary Function 0-Day Vulnerability Exploited in Attacks
Cyber Security News
GitLab 19.2.2 Patches 13 Security Flaws, Including High-Severity XSS and CI/CD Authorization Flaws
Cyber Security News
Jewelbug APT Hijacks Browsers to Steal Cookies and Spy on Government Networks
Expert Talks
Expert Talks
From Reactive Forensics to Predictive Defence: Strengthening Cyber Resilience in Banking
Expert Talks
Beyond the Lure: What the DoNot Campaign Reveals About Modern Cyber Espionage
Expert Talks
Your Incident Response Plan Has a Dependency You Never Approved
Expert Talks
Security in the AI Era Starts with First Principles
Cyber Security News
Planning Your AI Security – How will You Manage All Your Resources?