Mac malware wave keeps using ClickFix trick, researchers report
9to5Mac's latest Security Bite roundup finds that ClickFix, a technique tricking victims into pasting Terminal commands themselves, has become the default delivery method for nearly all new Mac stealer malware since the Q1 2026 review. Researchers at Group-IB, Huntress, and Kaspersky have each identified new malware families—including ClickLock, a Go-based stealer, and a MacSync variant disguised as Homebrew—all using this same social-engineering approach. The report notes attackers are adding persistence, backdoors, and infrastructure hidden inside Apple's own services.