Fake CleanMyMac Campaign Steals Mac Users’ Crypto Wallet Data and Personal Information
CleanMyMac is a macOS cleanup tool developed by MacPaw. Attackers created an imitation website and used ClickFix social engineering to trick users into pasting commands into Terminal, bypassing Gatekeeper, Apple notarization and XProtect. The threat is particularly serious because leaked recovery phrases could allow attackers to take direct control of wallet assets.
Malwarebytes disclosed on March 6, 2026, that the fake website, cleanmymacos.org, downloads SHub Stealer. The malware steals Apple Keychain contents, browser data and Telegram sessions, and scans for 23 wallet applications. It also tampers with applications including Ledger Live to capture recovery phrases. The report did not disclose the number of victims or the amount of losses.
All Coverage
1 original reportsThe Backstory
The history behind this eventClickLock Mac Malware Targets Crypto Wallets Across 33 Countries
ClickLock Stealer is a newly documented macOS information stealer that relies on social engineering rather than a software exploit. It is believed to arrive through ClickFix-style pages masquerading as Cloudflare verification checks, which persuade users to paste a malicious command into Terminal. The campaign matters because it turns trusted system prompts and built-in tools against Mac users, exposing browser credentials, password-manager data, Keychain material and cryptocurrency holdings while leaving a persistent backdoor.
Group-IB disclosed the malware on July 16, 2026, after finding a sample uploaded to VirusTotal on June 9 with zero detections at the time of analysis. The operation has been active since May and has targeted at least 100 victims in 33 countries, more than half in Europe. ClickLock can kill visible applications every 210 milliseconds until a user submits a login password, while harvesting data from 31 crypto-wallet browser extensions, eight desktop wallets and blockchain addresses across six networks for exfiltration through Telegram.
macOS Stealer CrashStealer Poses as Crash Reporter to Target Crypto Wallets
Cybersecurity company Jamf has uncovered CrashStealer, a new type of macOS malware that masquerades as the system's built-in crash-reporting tool to trick users into entering their passwords and granting access to the system keychain. The malware poses a significant threat because it specifically targets as many as 80 types of cryptocurrency wallets as well as browser credentials. It is also the first such malware to be developed using native C++ code, making it harder for traditional antivirus software to detect.
According to a Jamf Threat Labs investigation published in July 2026, researchers spotted signs that the malware was under development as early as May 2026 and found it had entered active deployment by early July. The malware bypassed system defenses using a malicious certificate that had passed Apple's notarization process. Apple revoked the associated developer certificates in mid-July to prevent further harm.
PamStealer Poses as macOS Tool to Steal Crypto Wallets
Malware attacks targeting Apple users have recently become frequent on macOS. A new infostealer called PamStealer masquerades as the popular open-source clipboard utility Maccy and uses macOS’s built-in Pluggable Authentication Modules, or PAM, mechanism to verify administrator privileges. It can specifically steal browser credentials and cryptocurrency wallets. Its ability to bypass system safeguards poses a major threat to users’ digital assets.
Jamf Threat Labs disclosed the malware in July 2026. Attackers created the fake website maccyapp[.]com to trick users into downloading it. The software packages an AppleScript that, when users follow instructions to run it in Script Editor, downloads a second-stage payload written in Rust. The payload impersonates system applications such as Finder to evade detection and steal private data in the background.
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.