216.73.216.6

Infiniti Stealer: a new macOS infostealer using ClickFix and Python/Nuitka

· Published 27/03/2026 09:42 · Modified 27/03/2026 09:59

Export JSON

Essential information

Published
27/03/2026 09:42
Modified
27/03/2026 09:59
Tags
2026-03-27 clickfix infiniti stealer infostealer macos nuitka
Related entities
1 vulnerabilities (cve), 2 observables, 3 malware

Description

A new called has been discovered, utilizing delivery and Python/ compilation. The malware spreads through a fake CAPTCHA page, tricking users into running a command themselves. The final payload is a Python-based stealer compiled with , making it harder to analyze and detect. The malware targets sensitive data including browser credentials, Keychain entries, cryptocurrency wallets, and developer files. It employs anti-analysis techniques and exfiltrates data via HTTP POST requests. This campaign demonstrates the adaptation of Windows-based techniques to target Mac users and showcases the increasing sophistication of malware.

External references