macOS ClickFix Attack Deploys Atomic Stealer to Steal Passwords and Crypto Wallets
A scam targeting Mac users is tricking people into installing harmful software by posing as a normal website verification step. It tells users to copy and run a command in the Mac Terminal, which can then steal saved passwords and cryptocurrency wallet information.
Who is at risk
Mac users are most at risk, especially anyone who visits unfamiliar websites and follows on-screen instructions to paste commands into Terminal.
What to watch for
Watch for websites that claim you must open Terminal and paste a command to prove you are human, unlock content, or complete a security check.
What to do
Do not paste or run commands in Terminal from a website, close the page immediately, and if you already did it, change important passwords right away and review financial or crypto accounts for suspicious activity.
