Skip to content
  • Blog Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form

Widespread Infostealer Campaign Targeting macOS Users

Posted on September 22, 2025September 22, 2025 By CWS

Menace actors are impersonating identified manufacturers in an ongoing, widespread marketing campaign aimed toward infecting macOS customers with info stealer malware, LastPass warns.

As a part of the an infection chain, the hackers are counting on fraudulent GitHub repositories claiming to supply macOS software program from varied firms and use search engine marketing (website positioning) in order that hyperlinks to the repositories seem on the high of search pages.

“Within the case of LastPass, the fraudulent repositories redirected potential victims to a repository that downloads the Atomic infostealer malware,” LastPass says.

LastPass recognized two GitHub websites impersonating its model, which have been posted on the Microsoft-owned code-sharing platform on 16 September, and which have been taken down since.

Each have been posted by a consumer named ‘modhopmduck476’ and contained hyperlinks claiming to allow customers to put in ‘LastPass on MacBook’, however redirected to the identical malicious web page.

A web page claiming to supply ‘LastPass Premium on MacBook’ was redirecting to macprograms-pro[.]com, the place customers have been instructed to repeat and paste a command right into a terminal window.

The command initiates a CURL request to an encoded URL, leading to an ‘Replace’ payload being downloaded to the Temp listing.

The payload was the Atomic macOS Stealer (AMOS) infostealer, which has been utilized in quite a few assaults since 2023. In August, CrowdStrike warned of a rise in fraudulent ads delivering a variant of AMOS known as SHAMOS.Commercial. Scroll to proceed studying.

LastPass has noticed the risk actors impersonating monetary establishments, password managers, know-how firms, AI instruments, cryptocurrency wallets, and different companies.

To evade detection, the risk actors used a number of GitHub usernames to create different pretend GitHub pages, which adopted an analogous naming sample, the place the identify of the focused firm and Mac-related terminology have been used.

The marketing campaign noticed by LastPass has been ongoing since at the very least July, when Deriv safety researcher Dhiraj Mishra warned that Homebrew customers have been focused with malicious advertisements resulting in a pretend GitHub repository.

The assaults, Mishra identified, exploited customers’ belief in Google Adverts and GitHub, and put in the official Homebrew software to cover the execution of a malicious payload within the background.

Associated: Telegram Rivaling Tor as House to Prison ‘Boards’

Associated: Apple, Netflix, Microsoft Websites ‘Hacked’ for Tech Assist Scams

Associated: Apple Rolls Out iOS 26, macOS Tahoe 26 With Patches for Over 50 Vulnerabilities

Associated: Apple Sends Contemporary Wave of Spy ware Notifications to French Customers

Security Week News Tags:Campaign, InfoStealer, macOS, Targeting, Users, Widespread

Post navigation

Previous Post: FBI Warns of Spoofed IC3 Website
Next Post: How to Gain Control of AI Agents and Non-Human Identities

Related Posts

Armis Raises $435 Million in Pre-IPO Funding Round at $6.1 Billion Valuation Security Week News
Apple Patches Major Security Flaws in iOS, macOS Platforms Security Week News
Ingram Micro Restores Systems Impacted by Ransomware Security Week News
Anubis Ransomware Packs a Wiper to Permanently Delete Files Security Week News
161,000 People Impacted by Krispy Kreme Data Breach Security Week News
Airoha Chip Vulnerabilities Expose Headphones to Takeover Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • NVIDIA VApp for Windows Vulnerability Let Attackers Execute Malicious Code
  • Cisco Identity Services Engine Vulnerability Allows Attackers to Restart ISE unexpectedly
  • Sandworm Hackers Attacking Ukranian Organizations with Data Wiper Malwares
  • AI Browsers Bypass Content PayWall Mimicking as a Human-User
  • Midnight Ransomware Decrypter Flaws Opens the Door to File Recovery

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • NVIDIA VApp for Windows Vulnerability Let Attackers Execute Malicious Code
  • Cisco Identity Services Engine Vulnerability Allows Attackers to Restart ISE unexpectedly
  • Sandworm Hackers Attacking Ukranian Organizations with Data Wiper Malwares
  • AI Browsers Bypass Content PayWall Mimicking as a Human-User
  • Midnight Ransomware Decrypter Flaws Opens the Door to File Recovery

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News