HeadlinesBriefing favicon HeadlinesBriefing.com

Mac Script Editor Exploited in ClickFix Malware Shift

AppleInsider •
×

Mac Script Editor becomes new attack vector for ClickFix malware, bypassing Apple's macOS 26.4 protections. Jamf reports attackers replaced Terminal commands with Script Editor workflows, using fake system cleanup prompts to deliver an Atomic Stealer variant. The attack chain begins with a browser-triggered applescript:// URL scheme, launching Script Editor via routine-looking permissions.

Victims receive storage optimization instructions masked as legitimate tasks, with obfuscated shell commands executing via tr, curl, and zsh. A Mach-O binary is dropped to /tmp, stripped of metadata, and executed. This evolution highlights gaps in Apple's layered security, as browser-initiated scripts remain unmonitored despite Terminal command scanning.