In the quiet architecture of everyday trust, a new macOS threat called AmnesiaStealer exploits the simple act of following instructions — luring users through counterfeit GitHub pages into pasting a command that opens the door to credential theft, file exfiltration, and ultimately, live remote control of their own browser. Identified by Jamf researchers in mid-August 2026, the malware represents a maturation of social engineering on Apple platforms: not a brute-force intrusion, but a patient manipulation of human habit. Its second stage, capable of puppeteering a victim's logged-in browser ses
AmnesiaStealer malware uses ClickFix to hijack macOS browsers with live remote control
The attacker can interact in real time using full keyboard and mouse inputs
Why does this malware bother with muting the system sound before it starts stealing?
It's about staying invisible. When Finder duplicates files, macOS plays an audio cue. If the user hears that sound repeatedly while they're not doing anything, they might open Activity Monitor and see what's running. Silence keeps the theft quiet.
The fake GitHub page—how does that actually fool someone?
It's social engineering at its most effective. Users expect to find download instructions on GitHub. They see what looks like an official page, they follow the steps. Pasting a command into Terminal feels technical enough to seem legitimate, and most users don't decode base64 strings to see what they're actually running.
What's the significance of the second stage, the browser hijacking?
That's where it becomes truly dangerous. Stealing passwords is one thing. But with live browser control, the attacker can log into your bank account, your email, your cryptocurrency exchange—anything you're already logged into—and do it in real time while you're not looking. They don't need your password; they just need your session.
The researchers mention the malware's code has debugging comments. What does that tell us?
The developer left notes in the code acknowledging Apple's patches and limitations. It suggests either carelessness or confidence—maybe they don't expect the code to be analyzed, or they're iterating quickly and don't bother cleaning up. Either way, it's a window into how the malware was built.
Why target so many different browsers instead of just Chrome?
Coverage. Different users prefer different browsers. By targeting Chrome, Brave, Edge, Arc, Opera, Vivaldi, and Chromium itself, the attacker maximizes the chance that whatever browser the victim uses, their data gets stolen. It's not sophisticated; it's thorough.
What does it mean that some of the malware's techniques no longer work on newer macOS versions?
It means the cat-and-mouse game is real. Apple patches vulnerabilities, and malware authors adapt. But they can't always adapt perfectly. The developer left comments showing frustration with newer OS versions blocking their techniques. That's actually useful information for defenders—it shows where Apple's protections are working.
The Pulse
- A fake GitHub download page tricks macOS users into pasting a base64 command into Terminal, silently launching a multi-stage infection that begins with reconnaissance and system sound muting before any theft occurs.
- AmnesiaStealer sweeps through Keychain passwords, Apple Notes, cryptocurrency wallets, Telegram sessions, and data from 16 Chromium-based browsers — using Finder duplication tricks to slip past permission restrictions.
- A second 'remote_stream' stage deploys live browser hijacking via Chrome DevTools Protocol, letting attackers puppet the victim's browser with full keyboard and mouse control while streaming a real-time screencast back to their panel.
- Some of the malware's bypass techniques have been blunted by newer macOS versions, and developer comments left in the code reveal the author's own frustration with these limitations — including a workaround that destroys victims' stored passwords rather than decrypting them.
- The attacker's command-and-control panel, titled 'Amnesia Panel,' returns Russian-language error messages on failed login, offering a tentative signal of operator origin, while researchers flag the working combination of data theft and browser control as warranting close surveillance.
In the quiet architecture of everyday trust, a new macOS threat called AmnesiaStealer exploits the simple act of following instructions — luring users through counterfeit GitHub pages into pasting a command that opens the door to credential theft, file exfiltration, and ultimately, live remote control of their own browser. Identified by Jamf researchers in mid-August 2026, the malware represents a maturation of social engineering on Apple platforms: not a brute-force intrusion, but a patient manipulation of human habit. Its second stage, capable of puppeteering a victim's logged-in browser sessions in real time, marks a meaningful escalation in what macOS-targeting adversaries are willing and able to build.
Security researchers at Jamf have uncovered AmnesiaStealer, a macOS infostealer that arrives through a disarmingly familiar scenario: a fake GitHub page for macOS software that instructs the visitor to copy a base64 string and paste it into Terminal. That single action fetches a dropper, which pulls down a password-protected ZIP containing the malware payload. The infection is quiet by design — before stealing anything, AmnesiaStealer mutes system sounds to suppress audio cues that might alert the user when files are being duplicated.
The malware then presents a convincing fake system prompt to harvest the user's password, which it validates against the system before beginning its sweep. Targets include the macOS Keychain, Apple Notes, documents with common extensions, cryptocurrency wallet data identified through pattern matching rather than hardcoded names, and Telegram session files. Browser data collection is especially thorough: 16 Chromium-based browsers are targeted, with the malware copying cookies, login data, history, bookmarks, and extension directories for every profile it finds. Where direct file access is blocked, it routes reads through Finder to sidestep permission restrictions.
What separates AmnesiaStealer from comparable macOS stealers is its second stage. When the attacker issues a 'remote_stream' command from their control panel, a module launches that uses the Chrome DevTools Protocol to spawn a headless browser cloned from the victim's own profile — inheriting all active logged-in sessions. Two WebSocket connections form a relay: one carries the operator's commands, the other streams a live screencast at three frames per second. The attacker gains full keyboard and mouse control, effectively operating the victim's browser in real time, and can harvest all cookies through the protocol for later import.
Newer macOS versions have blunted several of the malware's techniques, a fact the developer appears to acknowledge through debugging comments left in the code. One attempted exploit targets a Safari cookie bypass patched in macOS Catalina; another approach to recovering browser Safe Storage passwords fails entirely on macOS 26, prompting a destructive workaround that overwrites stored credentials rather than decrypting them. The attacker's control panel — hosted at the same domain used for distribution — returns error messages in Russian on failed login. Researchers concluded that despite its reliance on some aging bypasses, the functional pairing of data exfiltration and live browser hijacking makes AmnesiaStealer a threat worth watching closely.
Security researchers at Jamf have identified a new macOS malware called AmnesiaStealer that arrives through a deceptively simple trick: a fake GitHub page asking users to copy and paste a command into their Terminal. Once that command runs, the attack unfolds in stages, beginning with theft of passwords and sensitive files, then escalating to something far more invasive—live remote control of the victim's web browser while they're logged in.
The initial infection relies on the ClickFix social-engineering technique, which has proven effective at bypassing user skepticism. A victim lands on what appears to be a legitimate GitHub download page for macOS software. The page instructs them to copy a base64-encoded string and paste it into Terminal. That command fetches a dropper script, which downloads a password-protected ZIP file containing the AmnesiaStealer payload. The malware then executes, and the real work begins.
Before stealing anything, AmnesiaStealer performs reconnaissance and mutes the system sound—a deliberate step to prevent the user from hearing audio cues when files are duplicated in Finder. The malware then displays a fake system prompt claiming the "Installer wants to make changes," requesting the user's password. Once obtained and validated against the system, the stealer targets the Keychain (where macOS stores passwords and cryptographic material), Apple Notes, and files across the user's system. It hunts for documents with specific extensions—txt, pdf, rtf, doc, key, jpg, png, csv, and wallet files—using pattern matching to identify cryptocurrency wallet browser extensions without needing hardcoded wallet names. Telegram session data is also targeted.
The scope of browser data theft is particularly broad. AmnesiaStealer targets 16 distinct Chromium-based browsers, including Chrome, Brave, Arc, and Microsoft Edge. For each browser and profile, it copies the Extensions directory along with Cookies, Login Data, Web Data, History, Bookmarks, Local State, and Preferences files. The malware employs different techniques to access data it cannot reach directly—for instance, it uses the duplicate command to make Finder the process reading files, which bypasses certain permission restrictions. When attempting to steal Safari cookies, it tries the cat command first, then falls back to duplicate if that fails.
What distinguishes AmnesiaStealer from other macOS stealers is its second stage, triggered by a "remote_stream" command from the attacker's command-and-control panel. This stage deploys a module that grants live remote control of the victim's Chromium browsers through the Chrome DevTools Protocol. The attacker can spawn a headless version of the browser using a cloned copy of the victim's profile, meaning they inherit all logged-in sessions. Two WebSocket connections form a relay: one sends operator commands to the browser, the other streams a 3 frames-per-second screencast back to the attacker. The attacker can interact in real time using full keyboard and mouse inputs, effectively puppeteering the victim's browser. The module also steals cookies by calling Network.getAllCookies through the protocol, writing them to a Netscape cookie file that can be imported into the attacker's own browser.
Researchers noted that some of AmnesiaStealer's techniques have been blunted by Apple's security updates in newer macOS versions, including macOS 26 (Tahoe). Debugging comments left in the malware's code reveal the developer's awareness of these limitations. One technique attempts to exploit CVE-2020-9771, an APFS snapshot bypass for Safari cookie theft, but Apple patched this vulnerability in macOS Catalina 10.15.4 and 10.15.5. The exploit now only works if the Terminal or malware process already has Full Disk Access—a scenario that might occur with power users or developers. Another notable limitation: the malware attempts to recover the Safe Storage password for each browser to decrypt stored credentials, but the developer's comments indicate "no keys recovered" on macOS 26 and above. As a workaround, the malware overwrites the Safe Storage password with a hardcoded value, rendering all previously stored passwords and cookies inaccessible.
The attacker's command-and-control panel, discovered by researchers, is titled "Amnesia Panel" and was hosted at the same domain used to distribute the malware and remote control module. A failed login attempt returns an error message in Russian, suggesting the operator's origin. While AmnesiaStealer shares similarities with other macOS stealers like Atomic Stealer, MacSync, and CrashStealer, and uses comparable distribution methods, its combination of OS-version awareness and functional browser hijacking capability makes it a notable threat. Researchers concluded that the pairing of a working data collector with a working browser-control stage, even wrapped around some dated bypasses, warrants close monitoring.
Notable Quotes
A working collector paired with a working browser-hijack stage, wrapped around a few dated bypasses, makes it worth tracking— Jamf researchers
Because duplicate makes Finder the process that reads each file, these steps access data the malware cannot directly reach without prompting the user— Thijs Xhaflaire, Jamf Senior Threat and Detections Researcher