PULSE the living trend engine
▲ Peaking Technology

New AmnesiaStealer macOS malware hijacks browser sessions via remote control

A newly uncovered macOS malware named AmnesiaStealer targets Apple users through a fake GitHub download, granting attackers live browser control.

5sources
5articles
3velocity
+0%since first seen
2h agofirst detected

Velocity

How fast coverage is spreading — measured hourly from article rate × source diversity. How this works →

The brief

Recent reporting outlines the emergence of a new macOS malware variant identified as AmnesiaStealer, which targets Apple computer users through deceptive software downloads disguised as legitimate GitHub repositories. According to coverage from AppleInsider, thehackernews.com, TechRepublic, csoonline.com, and BleepingComputer, this malicious software specifically compromises Apple systems by executing a series of unauthorized actions once installed. The attack vector transforms standard Safari and Chrome browser sessions into conduits for data exfiltration, granting unauthorized third parties access to sensitive keychain data and active browser sessions on infected Mac computers. Coverage emphasizes the mechanics of the intrusion, noting that AmnesiaStealer successfully hijacks Chromium sessions to provide attackers with live, remote control over the compromised browser environment.

Outlets such as BleepingComputer and thehackernews.com detail how the malware operates beyond simple credential theft, enabling active manipulation of the victim's active web sessions. AppleInsider and TechRepublic highlight the specific danger posed to macOS users who rely on integrated browser keychain features for credential storage, while csoonline.com frames the threat as an evolution in how macOS endpoints are compromised through seemingly benign developer tools. Context provided across the reporting network indicates that this campaign exploits the trust users place in hosting platforms like GitHub, using fake download packages to bypass initial suspicion. The targeting of macOS ecosystems represents a continuous focus for threat actors seeking to extract high-value authentication tokens and sensitive keychain items from desktop environments that traditionally command a perception of enhanced security.

While the technical underpinnings involve sophisticated session hijacking, the current coverage does not yet specify the full scope of campaigns utilizing AmnesiaStealer or the exact group behind its deployment. Looking ahead, ongoing security analyses from the reporting outlets will likely monitor for additional indicators of compromise, broader distribution channels, or updates regarding remediation strategies for affected Mac systems. Observers and system administrators await further technical disclosures concerning how users can detect hidden persistence mechanisms associated with AmnesiaStealer. Current reporting outlines the immediate threat surface, leaving specific details regarding total infection numbers or mitigation patches to future security advisories and vendor responses.

Synthesized by PULSE from the headlines below under a strict no-invention contract. ✓ fact-checked: all claims supported by sources Updated 1h ago.

Quick answers

What is AmnesiaStealer?

AmnesiaStealer is a newly identified macOS malware that targets Apple computers to steal Keychain data and hijack browser sessions.

How does the malware infect systems?

Coverage states it spreads via a fake GitHub download that tricks users into installing the malicious payload.

Which browsers are affected?

Reports from AppleInsider and other outlets indicate the malware impacts both Safari and Chrome browsers on macOS.

Coverage (5)

Topics

Related trends