Quick Answer
AmnesiaStealer is a high-risk macOS infostealer that uses a fake GitHub download page and a ClickFix Terminal prompt to steal sensitive data and take hidden control of Chromium browser sessions. Jamf Threat Labs says the malware targets Keychain data, browsers, Apple Notes, and Telegram. Do not paste commands from download pages, and change passwords from a separate trusted device if you ran one.
Key Takeaways
- AmnesiaStealer spreads through a counterfeit GitHub page with a fake Verified Publisher badge.
- The ClickFix lure tells Mac users to paste a Base64-encoded command into Terminal.
- The Rust-based payload targets Keychain data, Apple Notes, Telegram, and browser information.
- The malware targets 16 Chromium-based browsers, including Chrome, Brave, Arc, and Edge.
- The stream_module can give an attacker hidden browser control through Chrome DevTools Protocol.
What is the AmnesiaStealer macOS malware?
AmnesiaStealer is a multi-stage macOS infostealer designed to steal personal data and hijack browser sessions. Jamf Threat Labs disclosed the Rust-based malware in August 2026 after identifying a campaign that relies on a counterfeit GitHub download experience and a social-engineering technique known as ClickFix. The attack is dangerous because it does not depend on a conventional app installation prompt alone. Instead, it persuades the victim to run a command directly in Terminal.
Jamf’s original AmnesiaStealer research describes a layered infection chain rather than a single malicious file. The first stage retrieves additional code, while later components collect information from the Mac and browser profiles. That design makes the initial page and Terminal instruction the critical point where a user can stop the compromise.
AmnesiaStealer is distinct from ordinary unwanted software because the reported capabilities include access to sensitive account material and active browser sessions. A stolen browser session can be especially serious because it may allow an attacker to act within a signed-in account without immediately needing the account password. The practical response is to treat any unknown Terminal command from a download page as unsafe until the software publisher confirms it through an official channel.
How does the fake GitHub page infect a Mac?
The fake GitHub page infects a Mac by convincing the visitor to paste an encoded command into Terminal. The counterfeit page displays a “Download for macOS” prompt and falsely presents a “Verified Publisher” badge, according to Jamf and reporting from The Hacker News. The visual design matters because GitHub branding and publisher labels can make an unfamiliar download appear legitimate.
The ClickFix instruction uses a Base64-encoded Terminal command, which retrieves a shell script and then a password-protected ZIP payload, according to The Hacker News. Base64 is an encoding format, not encryption, but encoded text makes a command harder for a typical user to inspect before running it. A password-protected archive can also make the downloaded payload less obvious during a quick review.
AmnesiaStealer relies on user action at this stage. A macOS security warning cannot protect a device if a user manually authorizes a command that downloads and launches the attacker’s files. The most sensible approach is to close any page that instructs you to open Terminal for a routine download, then locate the developer’s official site independently instead of following the page’s link.
Browser-based deception is not limited to macOS malware. Users who install browser tools should also review warnings about fake browser extensions, because a familiar brand, a positive-looking badge, or a polished download screen does not verify that a file is safe.
What data can AmnesiaStealer steal from a Mac?
AmnesiaStealer can collect Keychain data, browser information, Apple Notes, and Telegram data. Researcher Thijs Xhaflaire told The Hacker News that the first stage is a shell script and that the second stage is a Rust infostealer that harvests those sources. Keychain data is particularly sensitive because macOS uses Keychain to store credentials and other protected account information.
AmnesiaStealer also targets 16 Chromium-based browsers, including Chrome, Brave, Arc, and Microsoft Edge, according to the available reporting. Browser profiles can contain saved credentials, cookies, session information, browsing data, and extension-related records. The risk therefore extends beyond the browser that happened to be open when the malicious command ran.
| Targeted source | Reported AmnesiaStealer activity | Why the data matters | Safe response after exposure |
|---|---|---|---|
| macOS Keychain | Harvests Keychain data | Keychain can hold protected credentials and account material. | Change important passwords from a separate trusted device. |
| Chromium browsers | Targets 16 browser families and profiles | Browser profiles can contain saved logins, cookies, and active sessions. | Sign out of important accounts and review active sessions. |
| Apple Notes | Harvests Apple Notes data | Notes may contain recovery codes, personal records, or account details. | Review notes for sensitive information and replace exposed recovery codes. |
| Telegram | Harvests Telegram-related data | Messaging data can expose conversations and account access information. | Review the account from a trusted device and remove unfamiliar sessions. |
The most important limitation is that the public reporting describes the malware’s capabilities, not every individual victim’s outcome. A user who ran the command should still assume sensitive information could have been accessed, because waiting for visible account abuse gives an attacker more time to use stolen data.
How does AmnesiaStealer hijack browser sessions?
AmnesiaStealer can clone a browser profile and use Chrome DevTools Protocol to give an attacker hidden remote control of the session. SecurityWeek reports that the malware includes a component called “stream_module,” which uses the Chrome DevTools Protocol, commonly called CDP, to interact with the victim’s browser. CDP is a legitimate browser debugging interface, but malware can misuse it to control a browser profile after gaining access to the Mac.
The reported stream_module provides the attacker with a hidden view of the browser and roughly a 3fps screencast, according to SecurityWeek’s report on the browser-control feature. Three frames per second is not equivalent to a smooth video call, but it can still reveal enough screen activity for an operator to monitor pages, prompts, and account workflows. The attacker can use that visibility alongside browser control to interact with a logged-in session.
CSO Online reports that the malware can export browser cookies in plaintext through the DevTools Protocol after the stream module activates. Cookies can function as session identifiers, which is why changing only a password may not fully remove risk until the affected account sessions are also revoked. The practical response is to use a separate trusted device to sign out of active sessions for email, financial, work, cloud-storage, and messaging accounts.
Why is browser session theft more serious than a password leak?
Browser session theft can give an attacker access to an account that is already authenticated. A password leak often requires the attacker to enter the password and satisfy additional protections, while a stolen session cookie may represent an existing signed-in browser session. AmnesiaStealer’s reported browser-control capability increases the concern because the attacker may be able to observe or manipulate the session rather than merely copy stored credentials.
Two-factor authentication remains valuable, but browser session theft shows why it is not a complete recovery plan after a device compromise. A user can approve a sign-in challenge and still face risk if the attacker already controls an active browser profile. The appropriate sequence is to revoke sessions, change passwords, replace recovery codes where appropriate, and confirm that account recovery details have not changed.
Account data theft also creates follow-on phishing risk. An attacker who can view notes, browser activity, or messaging information may have enough context to write a convincing fraudulent message. Users should be cautious about unexpected requests for codes, money, or password resets, especially after a device security incident. Broader data breach risk often begins with exposed account information that is later reused for fraud or impersonation.
What should Mac users do after running the command?
Mac users who ran the AmnesiaStealer command should treat the Mac and its browser sessions as compromised. Stop entering passwords, recovery codes, payment information, or confidential work data on the affected Mac until you have completed recovery from a separate trusted device. The malware’s reported ability to access browser profiles means changing a password on the same potentially infected system can expose the replacement credential.
- Disconnect the affected Mac from the internet to limit further communication with an attacker.
- Use a separate trusted device to change passwords for email, password-manager, financial, work, cloud-storage, and messaging accounts.
- Revoke active sessions for important accounts, because password changes alone may not invalidate every stolen browser session.
- Review account recovery email addresses, phone numbers, connected devices, and recent sign-in activity for unauthorized changes.
- Document the suspicious page, command, and time of infection before deleting files or changing the system.
AmnesiaStealer recovery should not end with closing the browser or deleting the downloaded archive. The reported infection chain includes a shell script and later payloads, so a visible file may not represent every component that ran. A user who stores work credentials, financial information, or highly sensitive personal data on the Mac should stop here and contact an Apple support channel, employer security team, or qualified incident-response professional before relying on the device again.
How can Mac users avoid ClickFix malware?
Mac users can avoid ClickFix malware by refusing Terminal commands supplied by download pages, pop-ups, or supposed verification screens. Legitimate software documentation can contain Terminal instructions for advanced tasks, but a routine download page should not require an encoded command to prove that a visitor is human or unlock an installer. The warning sign is the request to copy and paste text that the page does not explain in plain language.
AmnesiaStealer’s fake GitHub template reportedly resembles pages used in earlier Atomic, also called AMOS, and MacSync infostealer campaigns. BleepingComputer’s coverage of the reused template notes that the same general deception pattern has appeared before. Reused page designs matter because a campaign can change its malware payload while keeping a social-engineering format that has already succeeded.
Mac users should verify downloads by typing the publisher’s official website into the browser or using a known official source, rather than trusting a search result or advertisement. Mac users should also inspect unfamiliar browser extensions and avoid granting access to sensitive accounts from an untrusted browser profile. The practical rule is simple: stop when a website asks you to run a command you do not understand.
What should organizations do about AmnesiaStealer?
Organizations should warn Mac users about fake GitHub downloads and investigate any report of a pasted Terminal command immediately. AmnesiaStealer depends on social engineering at the beginning of the infection chain, so employee awareness is part of the defense. A short internal alert should name the fake Verified Publisher badge, the ClickFix prompt, and the instruction to paste Base64 text into Terminal.
Security teams should prioritize accounts that could have been accessible through the affected browser profile. Those accounts include corporate email, collaboration tools, cloud consoles, source-code services, and administrative portals. The reason is not merely that passwords may be stored in the browser. The reported browser-session capabilities mean a valid authenticated session could require revocation even after a password reset.
Organizations should also preserve evidence and follow their incident-response process before making broad changes to the device. An employee should not attempt advanced cleanup or make assumptions about the scope of compromise. A corporate security team or incident-response provider should handle the investigation if the Mac accessed business systems, because the organization may need to identify affected accounts, browser sessions, and connected services.
FAQ
Is AmnesiaStealer a real macOS threat?
Yes, AmnesiaStealer is a newly disclosed macOS infostealer documented by Jamf Threat Labs. The malware uses a fake GitHub page and a ClickFix Terminal command to deliver a multi-stage payload.
Does AmnesiaStealer target Google Chrome?
Yes, AmnesiaStealer targets Chrome and 15 other Chromium-based browsers, including Brave, Arc, and Edge. The malware reportedly clones browser profiles and can abuse Chrome DevTools Protocol for hidden browser control.
Can changing my password remove AmnesiaStealer access?
No, changing a password alone may not remove AmnesiaStealer access if an attacker has stolen an active browser session. Revoke active sessions from a separate trusted device and review recovery details after changing passwords.
Should I paste a command into Terminal to download an app?
No, a download page that asks you to paste an unfamiliar command into Terminal is a significant warning sign. Verify the software through the developer’s official website before running any command you do not understand.
Should I factory-reset a Mac after an AmnesiaStealer infection?
Yes, a full rebuild may be appropriate after a confirmed AmnesiaStealer infection, but a qualified security professional should guide recovery when sensitive accounts or work systems were involved. Do not rely on deleting the visible download because the reported infection chain includes multiple stages.
