Вход на сайт

Просмотр новости

Найдите то, что Вас интересует

This Malware Can Take Over Web Browsers on macOS, but You Can Protect Yourself

Дата публикации: 17-08-2026 16:44:42

AmnesiaStealer is spreading via ClickFix.

Основное содержимое страницы с новостью.

Emily Long

Emily Long Freelance Writer

Experience

Emily Long is a freelance writer based in Salt Lake City.

After graduating from Duke University, she spent several years reporting on the federal workforce for Government Executive, a publication of Atlantic Media Company, in Washington, D.C. She has nearly a decade of experience as a freelancer covering tech (including issues related to security, privacy, and streaming) as well as personal finance and travel.

In addition to Lifehacker, her work has been featured on Wirecutter, Tom’s Guide, and ZDNET. Emily has also worked as a travel guide around the U.S. and as a content editor. She has a masters in social work and is a licensed therapist in Utah.

Read Full Bio

August 17, 2026

Add as a preferred source on Google
Add as a preferred source on Google

person typing on a macbook

Credit: Perawit Boonchu / iStock via Getty Images

Key Takeaways

  1. Hackers are pushing an infostealing malware to macOS users that is capable of hijacking your sessions in Google Chrome and other browsers.
  2. AmnesiaStealer can copy a victim's Chromium profile, which allows it to collect data, access authenticated sessions, and control them remotely.
  3. The best way to protect yourself from AmnesiaStealer is to be vigilant against ClickFix attacks.
Table of Contents

In a new ClickFix attack iteration, hackers are pushing an infostealing malware to macOS users that is capable of hijacking your sessions in Google Chrome, Microsoft Edge, and a number of other Chromium-based browsers. AmnesiaStealer grants remote control of your browser and access to plenty of personal data, so you should know how to spot the campaign and protect your device from compromise.

AmnesiaStealer hijacks your web browser on macOS

As BleepingComputer reports, AmnesiaStealer can copy a victim's Chromium profile, which allows it to collect data across 16 Chromium-based web browsers, access authenticated sessions, and control them remotely. This means threat actors can navigate across websites, export or import cookies, and access online portals as well as grab saved logins, history, bookmarks, extensions, and cryptocurrency wallet data. AmnesiaStealer can also capture your macOS password and gain access to keychain data, Apple Notes, Telegram sessions, documents, and system information.

Researchers at security company Jamf found that hackers are distributing the malware via a password-protected ZIP archive on a fake GitHub page and are gaining this level of access when users run a Terminal command that downloads and installs the payload. The campaign mirrors previously identified Atomic and MacSync infostealers.

How to avoid browser takeover attempts

The best way to protect yourself from AmnesiaStealer is to be vigilant against ClickFix attacks, which use social engineering tactics to deliver malware to your device. Common tricks include fake error messages, CAPTCHA forms, and, as in this case, command prompts that install malicious payloads that can then spy on your activity, steal your data, and take over your machine.

What do you think so far?

Threat actors count on you believing that these commands do something innocuous (like download legitimate software) or not understanding what you're executing on your device. That's why you should be highly skeptical of any prompts you find online and never execute commands in Terminal from non-official sources. Note that the fake GitHub page being used to distribute AmnesiaStealer has a "Verified Publisher" tag to gain user trust. Fraudsters will also try to impersonate legitimate companies—tech support scams are one example—so you should never copy and paste commands in your system dialogue even if you believe you're interacting with a trusted business or service.

Lifehacker Logo

Lifehacker has been a go-to source of tech help and life advice since 2005. Our mission is to offer reliable tech help and credible, practical, science-based life advice to help you live better.

© 2001-2026 Ziff Davis, LLC., A ZIFF DAVIS COMPANY. ALL RIGHTS RESERVED.

Lifehacker is a federally registered trademark of Ziff Davis and may not be used by third parties without explicit permission. The display of third-party trademarks and trade names on this site does not necessarily indicate any affiliation or the endorsement of Lifehacker. If you click an affiliate link and buy a product or service, we may be paid a fee by that merchant.

Схожие новости

#Наименование новостиТональностьИнформативностьДата публикации
1 Dangerous new CrashStealer Mac impersonates Apple's own tools — and bypasses Gatekeeper — to steal your passwords and more -5715-07-2026
2Hackers Are Screen Sharing on Macs Without Permission, but You Can Stop Them07.8317-08-2026
3Fake GitHub download turns Safari & Chrome into a Keychain data stealer08.813-08-2026
4CrashStealer malware masquerades as Apple’s crash report tool to raid your Mac-2714-07-2026
5AI Browsers Vulnerable to 'PleaseFix' Zero-Click Agent Hijacking011.0405-08-2026
6Root получен без единого клика — критическая уязвимость macOS уже в деле01018-08-2026
7PSA: Beware of fake Mac crash reports out to steal your passwords, crypto wallets, more07.715-07-2026
8Vulnerability giving attackers full control of Macs is under active exploitation01014-08-2026
9Hackers exploit macOS Screen Sharing flaw to deploy Monero miner08.3114-08-2026
10Hackers exploit macOS Screen Sharing vulnerability — update your Mac ASAP021.4317-08-2026

Классификация: Общество. Схожих патентов: 0. Схожих новостей: 10. Тональность: 0. Информативность: 8.98. Источник: skillet.lifehacker.com.