HeadlinesBriefing favicon HeadlinesBriefing.com

Fake GitHub download steals Safari & Chrome data

AppleInsider •
×

Jamf Threat Labs uncovered a Mac malware dubbed AmnesiaStealer that steals sensitive data and launches a hidden copy of the victim’s Chrome or Safari, letting attackers hijack already‑unlocked accounts. The three‑stage infection first lands on a counterfeit GitHub‑styled page that instructs users to paste a terminal command. After the user runs the command and supplies a valid password, the payload uses the credentials to access Keychain, browser data, Apple Notes, Telegram sessions, and personal files. Unlike typical infostealers, it doesn’t exploit a macOS vulnerability; the user’s cooperation is required.

In lab tests, AmnesiaStealer cloned a Chromium profile into a hidden directory and launched the browser in headless mode, controlling it via the Chrome Dev Tools Protocol. The operator gained a live view of the session and could export decrypted cookies, re‑inject them, or manipulate the user’s browsing state. The malware supports Chrome, Brave, Edge, Arc, Opera, Vivaldi and Chromium, and can rewrite encrypted cookies directly, though this failed on macOS 26.

The tool also collects hardware identifiers, OS version, installed apps, and scans Documents, Desktop and Downloads for valuables, including wallet files, keys and images. It bundles the stolen data into a compressed archive before exfiltration. Attackers can’t spread the malware without the user’s terminal command, so avoiding suspicious downloads and verifying source URLs remains the best defense.