MacSync: The Evasive macOS Stealer Exploiting ClickFix Lures

Published September 8, 2026

MacSync is a macOS malware that steals passwords, browser data, and crypto wallets. Attackers trick users into running malicious Terminal commands by faking prompts from Google Meet, Claude AI, and other trusted services.

Report priority
High
Targets
Technology+1 more

How it works

  • Attackers send fake pop-up prompts on websites or apps pretending to be Google Meet, Claude AI, Docker, or TradingView.
  • These prompts trick users into typing a Terminal command that downloads and runs MacSync malware.
  • Once installed, MacSync hides itself by running as a background process, avoids Apple's security checks, and steals passwords, browser data, cryptocurrency wallets, and SSH keys.
  • It then sends the stolen data in small chunks to attackers' servers.

What to do

If you clicked a fake prompt on a website or app pretending to be Google Meet, Claude AI, Docker, or TradingView, then ran a Terminal command it suggested, check your Terminal history for unknown commands like brew install --cask or curl commands from unfamiliar sites. Also look for new files in /Applications or /usr/local/bin that you don't recognize.

If you ran a suspicious command, immediately restart your Mac in Safe Mode (hold Shift at startup) to prevent MacSync from running. Then scan your system with a trusted antivirus like Malwarebytes or XoftSpySE. Update your macOS to the latest version and enable Gatekeeper to block unsigned apps. If you suspect your data was stolen, change passwords for all accounts and enable two-factor authentication where possible. For help, contact Apple Support or your IT department.

Technical details

Affected software: Technology, Finance

A victim visits a hacked website or opens a fake app that shows a fake Google Meet prompt. The prompt tells them to run a Terminal command like brew install --cask google-meet to fix a supposed issue. The command actually downloads and installs MacSync, which then steals their data and sends it to attackers.

MacSync is a macOS malware family acting as an information stealer and remote-access trojan, distributed via ClickFix social engineering and malvertising campaigns. It employs evasion techniques such as process daemonization, single-byte XOR obfuscation, and in-memory AppleScript execution to bypass Apple's security mechanisms like Gatekeeper, XProtect, and endpoint detection and response (EDR) solutions. Once deployed, the malware steals credentials, browser data, cryptocurrency wallet details, and SSH keys, transmitting the stolen data in 10MB chunks to command-and-control (C2) servers.

The malware targets professionals in software engineering, cryptocurrency, fintech, and corporate sectors across North America, Europe, and Asia-Pacific. Attackers impersonate legitimate services, such as Google Meet, Claude AI, Docker, and TradingView, to trick victims into running malicious Terminal commands. The threat operates under a malware-as-a-service model, allowing operators to deploy and manage the stealer efficiently.

The OTX identifier for this threat is OTX-6a9fff8d4e576223ee6f9b4e4.