A multi-stage malware known as AmnesiaStealer has been discovered targeting macOS users via a fake GitHub download page. This information stealer employs a three-stage infection chain involving a shell script that executes the payload to harvest user data and gain control over web browsers. Key differentiators include its builder-driven configuration, exploits aimed at bypassing security measures on macOS, and an interactive remote control capability.
It specifically targets Chromium-based browsers like Chrome and Edge to overwrite stored passwords and cookies, making them unrecoverable. The malware also utilizes an old vulnerability to steal Safari cookies and maintain persistence through a LaunchDaemon.