macOS ClickFix Crimekit Uses Polygon Smart Contracts to Deploy AMOS Stealer and XMRig Miner

Published August 19, 2026

Attackers are tricking Mac users into pasting a command into Terminal after a fake human-verification check, which secretly installs malware. The malware steals saved passwords and browser data, runs a cryptocurrency miner, and hides its control server inside a public blockchain instead of a normal web address.

Report priority
Medium
Targets
Polygon+1 more

How it works

A fake CAPTCHA page copies a malicious command to the clipboard and tells the visitor to open Terminal, paste it, and press Return, which runs a script that downloads and installs the malware without any file the person has to double-click.

What to do

If you recently visited a suspicious human-verification page and were told to open Terminal and paste a command, never paste clipboard content into Terminal from a verification page. If you did, remove the LaunchAgent, change any passwords stored in the browser or Keychain, and consider reinstalling macOS or getting help from a security professional. Check for a LaunchAgent file named com.ifipbqmfnnywqguz in your user Library folder and a file called.passphrase in your home folder.

Technical details

Affected software: Polygon, XMRig

The loader avoids hardcoded command-and-control domains by issuing read-only eth_call requests to a Polygon smart contract at 0xA3a603F8a454a9c905b4c579Bb72628F7C15C2A0, retrieving the live C2 hostname (67sixcebeh.surf at time of analysis) via getter selector 0x2686ecea, a technique known as EtherHiding. The initial AppleScript loader is delivered through a curl-to-bash pipeline from a Cloudflare Worker and persists via a LaunchAgent (com.ifipbqmfnnywqguz) with RunAtLoad/KeepAlive. A persistent agent module (bmodule) fingerprints the host via IOPlatformUUID, phishes credentials through a fake System Preferences dialog validated with dscl. authonly, resets TCC permissions with tccutil reset All, and can deploy AMOS stealer variants (smodule, lmodule), XMRig mining (ledger), or an interactive shell.