This Sneaky macOS Attack Is Draining Crypto Wallets and Stolen Passwords

·
Listen to this article~4 min

A Go-based malware delivered via ClickFix attacks is targeting macOS users, stealing crypto assets, browser passwords, and Apple Keychain data. Here's how to protect yourself.

Another day, another macOS threat that's flying under the radar. This time, it's a Go-based malware delivered through something called a ClickFix attack, and it's not just after your files. It's targeting cryptocurrency assets, browser-stored passwords, Apple Keychain data, and cached credentials. If you're a Mac user who dabbles in crypto or relies on your browser to remember logins, this one deserves your attention. ClickFix attacks are clever because they don't look like malware at first glance. You're on a website, maybe a compromised forum or a fake download page, and a popup appears claiming your browser has an issue. The fix? Copy a command and paste it into your terminal. That's the trap. Once you do, you're executing the attacker's code without realizing it. ### How the Attack Unfolds The malware itself is written in Go, which makes it fast and harder to analyze. It doesn't need to be particularly complex to do serious damage. Once it's on your system, it quietly goes to work, scanning for anything valuable. Here's what it's after: - Cryptocurrency wallet files and browser extensions - Passwords saved in Chrome, Safari, or other browsers - Apple Keychain data, including Wi-Fi passwords and app credentials - Cached credentials from various services What makes this particularly nasty is the breadth of targets. It's not just about emptying one wallet or stealing one password. The malware is designed to harvest everything it can, giving attackers a full picture of your digital life. ### The Crypto Angle For anyone holding crypto, this is a direct threat. The malware specifically looks for wallet-related files and browser extensions like MetaMask or Phantom. If it finds them, it can potentially drain funds or steal private keys. And because the attack runs locally, there's no way for a remote service to block it. ### Why macOS Isn't Immune There's a long-standing myth that Macs don't get viruses. That's simply not true. While macOS has solid built-in protections, social engineering attacks like ClickFix bypass those safeguards by tricking the user into running the malicious command. No amount of built-in security helps if you're the one typing the command into the terminal. ### What You Can Do Right Now If you think you might have fallen for something like this, or you just want to be prepared, here are a few practical steps: - **Don't paste unknown commands into your terminal.** Legitimate websites don't ask you to run scripts to fix browser issues. - **Use a dedicated password manager** instead of relying on browser autofill. This adds a layer of separation between your credentials and any malware that might be running. - **Enable two-factor authentication** on your crypto exchange accounts and wallets. It's not foolproof, but it adds friction. - **Keep your system updated.** Apple regularly patches known vulnerabilities, so staying current matters. - **Consider a separate, offline wallet** for larger crypto holdings. Hot wallets are convenient, but they're also more exposed. ### The Bigger Picture This isn't just about one piece of malware. It's a reminder that the attack surface is expanding. Cybercriminals are getting better at targeting specific platforms and user behaviors. macOS users are no longer bystanders; they're active targets. The key takeaway is simple: be skeptical of anything that asks you to run a command or download a "fix" from a random website. The cost of being cautious is a few seconds of your time. The cost of being careless could be your entire crypto portfolio and access to your most sensitive accounts. Stay sharp out there. Your digital life depends on it.