GoPlus: A malicious program uses ClickFix to attack Mac users and steal crypto wallets
Foresight News reported that GoPlus has issued a security warning: the malicious program Infiniti Stealer is currently targeting the crypto wallets of Mac users. This program employs social engineering tactics known as “ClickFix,” luring users to execute malicious commands in the terminal by impersonating a Cloudflare CAPTCHA page.
After executing the command, the attack chain removes macOS’s quarantine attribute and runs its payload in the background. The final payload is a Python theft program compiled into a native binary via Nuitka, which offers strong detection evasion capabilities. Infiniti Stealer collects browser credentials, macOS Keychain, crypto wallets, and developer keys (such as .env files), and features sandbox detection and delayed execution.
GoPlus advises users to follow the principles of “do not click, do not install, do not sign, do not transfer,” check for persistent files in the /tmp and ~/Library/LaunchAgents/ directories, and reset credentials promptly.
Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.
You may also like
Market Chatter: Meta Platforms Looking to Launch Camera-Free Smart Glasses This Fall
Are space stocks like SpaceX and Rocket Lab about to get a boost? The US confirms its first on-orbit space weapon, accelerating the "Iron Dome" program.
The U.S. military has, for the first time, publicly confirmed that the United States now possesses an on-orbit "space control weapon," and the "Iron Dome" space-based interceptor project has advanced to the "flyable hardware" stage.

Brightstar Lottery to Buy Back $395 Million of Euro-Denominated Senior Notes in Tender Offer
Euro gains against Canadian Dollar as oil prices retreat on rising US crude inventories
