Introducing MERENA+ — our premium tier with your personalized safety dashboard, risk score, and all security tools. Sign up and cancel risk free in the first 14 days on the annual plan.Learn More
MERENA
Immediate Action Alert

AmnesiaStealer macOS Malware Hijacks Browser Sessions via Fake GitHub Lure

A harmful scam targeting Mac users is using a fake GitHub download page to trick people into pasting a command into Terminal, which can secretly install software that steals information and lets criminals control web sessions. This means attackers may be able to access accounts you are logged into without needing your password again.


Who is at risk

Mac users who download software from links they find online, especially from pages that appear to be GitHub or developer download sites, are most at risk.

What to watch for

Watch for download instructions that tell you to open Terminal and paste a command, unexpected login activity, browser sessions that seem to stay open, or account alerts for sign-ins you do not recognize.

What to do

Do not paste commands into Terminal from websites, close and sign out of important accounts if you already did, change your passwords from a trusted device, and remove any recently installed unknown software.