Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Widespread Infostealer Campaign Targeting macOS Users

Widespread Infostealer Campaign Targeting macOS Users

Posted on September 22, 2025September 22, 2025 By CWS

Menace actors are impersonating identified manufacturers in an ongoing, widespread marketing campaign aimed toward infecting macOS customers with info stealer malware, LastPass warns.

As a part of the an infection chain, the hackers are counting on fraudulent GitHub repositories claiming to supply macOS software program from varied firms and use search engine marketing (website positioning) in order that hyperlinks to the repositories seem on the high of search pages.

“Within the case of LastPass, the fraudulent repositories redirected potential victims to a repository that downloads the Atomic infostealer malware,” LastPass says.

LastPass recognized two GitHub websites impersonating its model, which have been posted on the Microsoft-owned code-sharing platform on 16 September, and which have been taken down since.

Each have been posted by a consumer named ‘modhopmduck476’ and contained hyperlinks claiming to allow customers to put in ‘LastPass on MacBook’, however redirected to the identical malicious web page.

A web page claiming to supply ‘LastPass Premium on MacBook’ was redirecting to macprograms-pro[.]com, the place customers have been instructed to repeat and paste a command right into a terminal window.

The command initiates a CURL request to an encoded URL, leading to an ‘Replace’ payload being downloaded to the Temp listing.

The payload was the Atomic macOS Stealer (AMOS) infostealer, which has been utilized in quite a few assaults since 2023. In August, CrowdStrike warned of a rise in fraudulent ads delivering a variant of AMOS known as SHAMOS.Commercial. Scroll to proceed studying.

LastPass has noticed the risk actors impersonating monetary establishments, password managers, know-how firms, AI instruments, cryptocurrency wallets, and different companies.

To evade detection, the risk actors used a number of GitHub usernames to create different pretend GitHub pages, which adopted an analogous naming sample, the place the identify of the focused firm and Mac-related terminology have been used.

The marketing campaign noticed by LastPass has been ongoing since at the very least July, when Deriv safety researcher Dhiraj Mishra warned that Homebrew customers have been focused with malicious advertisements resulting in a pretend GitHub repository.

The assaults, Mishra identified, exploited customers’ belief in Google Adverts and GitHub, and put in the official Homebrew software to cover the execution of a malicious payload within the background.

Associated: Telegram Rivaling Tor as House to Prison ‘Boards’

Associated: Apple, Netflix, Microsoft Websites ‘Hacked’ for Tech Assist Scams

Associated: Apple Rolls Out iOS 26, macOS Tahoe 26 With Patches for Over 50 Vulnerabilities

Associated: Apple Sends Contemporary Wave of Spy ware Notifications to French Customers

Security Week News Tags:Campaign, InfoStealer, macOS, Targeting, Users, Widespread

Post navigation

Previous Post: FBI Warns of Spoofed IC3 Website
Next Post: How to Gain Control of AI Agents and Non-Human Identities

Related Posts

Pixnapping Attack Steals Data From Google, Samsung Android Phones Pixnapping Attack Steals Data From Google, Samsung Android Phones Security Week News
Organizations Warned of Exploited Linux Vulnerabilities Organizations Warned of Exploited Linux Vulnerabilities Security Week News
SAP Patches Critical Flaws That Could Allow Remote Code Execution, Full System Takeover SAP Patches Critical Flaws That Could Allow Remote Code Execution, Full System Takeover Security Week News
Scattered Spider Activity Drops Following Arrests, but Others Adopting Group’s Tactics Scattered Spider Activity Drops Following Arrests, but Others Adopting Group’s Tactics Security Week News
Evidence Suggests Exploitation of CitrixBleed 2 Vulnerability Evidence Suggests Exploitation of CitrixBleed 2 Vulnerability Security Week News
Netskope Raises Over 8 Million in IPO Netskope Raises Over $908 Million in IPO Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Muddled Libra Exploits VMware vSphere in Cyber Attack
  • Feiniu NAS Devices Targeted in Major Botnet Attack
  • Rapid SSH Worm Exploits Linux Systems with Credential Stuffing
  • Odido Telecom Hacked: 6.2 Million Accounts Compromised
  • Lazarus Group Targets npm and PyPI with Malicious Packages

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Muddled Libra Exploits VMware vSphere in Cyber Attack
  • Feiniu NAS Devices Targeted in Major Botnet Attack
  • Rapid SSH Worm Exploits Linux Systems with Credential Stuffing
  • Odido Telecom Hacked: 6.2 Million Accounts Compromised
  • Lazarus Group Targets npm and PyPI with Malicious Packages

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News