
Mac malware ClickLock Stealer tricks users into surrendering passwords with fake prompts
Security researchers have detected ClickLock Stealer, a macOS malware that relies on social engineering rather than exploits: victims are duped into pasting a command into Terminal via a fake ClickFix/Cloudflare check, which then downloads modules and shows a fake progress bar. If users dismiss the password prompt, the system is locked; if they grant access to a Keychain item, the malware retrieves Chrome’s Safe Storage AES key to harvest passwords, cookies, password-manager data and crypto wallets, sending the data to a Telegram bot and installing a hidden backdoor. The campaign has been active since May 2026 across 33 countries, and Apple has added paste-warning protections in macOS Tahoe 26.4 to block pastes from suspicious sites.