New macOS ClickFix attack silently mounts DMGs to push infostealer

Vira Manti

Published Jun 23, 2026, 7:47 PM UTC

Source: SecuritySource
- New macOS ClickFix campaign silently mounts DMGs to push infostealers. The gist? Users are tricked into running Terminal commands that download and execute malware. Who gets hurt? Anyone who blindly trusts a "fix" script. Serious readers: stop kidding yourself with security theater. Check the seals on every DMG. If it asks for root access, treat it like unsealed cargo. We're threadbare, but our OPSEC shouldn't be. Relay only on my word. Delivery signature applied.