216.73.216.6

MacSync Stealer Returns: SEO Poisoning and Fake GitHub Repositories Target macOS Users

· Published 26/01/2026 08:54 · Modified 26/01/2026 09:21

Export JSON

Essential information

Published
26/01/2026 08:54
Modified
26/01/2026 09:21
Tags
2026-01-26 applescript github infostealer macos macsync pagerduty seo poisoning windows
Related entities
3 observables, 9 techniques (mitre), 1 malware, 7 others

Description

An active campaign is targeting and users across various sectors. The threat actors are using to direct victims to fake repositories impersonating legitimate tools like . The campaign involves over 20 malicious repositories active since September 2025. The attack flow begins with a Google search, leading to a fraudulent repository, then to a Pages site with a deceptive command. This command deploys the stealer in three stages: a loader, a dropper, and the final payload. aggressively harvests credentials from browsers, cloud services, and cryptocurrency wallets. The campaign's scale includes 39 identified malicious repositories, with 24 still active as of January 2026. Evasion tactics include using 'readme-only' repositories and distributed identities.

External references