Fake GitHub download turns Safari & Chrome into a Keychain data stealer
Jamf Threat Labs has found Mac malware that steals sensitive data and secretly launches a controllable copy of the victim's Chrome or Safari installs, giving attackers a way into accounts that are already unlocked.AmnesiaStealer
Jamf's August 5 report describes a three-stage AmnesiaStealer infection observed in the wild. The attack begins on a counterfeit GitHub page that tells visitors to paste a command into Terminal.AmnesiaStealer then displays a fraudulent installer prompt and uses the captu
Read more »