New AmnesiaStealer macOS malware hijacks browser sessions via remote control
A newly uncovered macOS malware named AmnesiaStealer targets Apple users through a fake GitHub download, granting attackers live browser control.
Velocity
How fast coverage is spreading — measured hourly from article rate × source diversity. How this works →
The brief
Recent reporting outlines the emergence of a new macOS malware variant identified as AmnesiaStealer, which targets Apple computer users through deceptive software downloads disguised as legitimate GitHub repositories. According to coverage from AppleInsider, thehackernews.com, TechRepublic, csoonline.com, and BleepingComputer, this malicious software specifically compromises Apple systems by executing a series of unauthorized actions once installed. The attack vector transforms standard Safari and Chrome browser sessions into conduits for data exfiltration, granting unauthorized third parties access to sensitive keychain data and active browser sessions on infected Mac computers. Coverage emphasizes the mechanics of the intrusion, noting that AmnesiaStealer successfully hijacks Chromium sessions to provide attackers with live, remote control over the compromised browser environment.
Outlets such as BleepingComputer and thehackernews.com detail how the malware operates beyond simple credential theft, enabling active manipulation of the victim's active web sessions. AppleInsider and TechRepublic highlight the specific danger posed to macOS users who rely on integrated browser keychain features for credential storage, while csoonline.com frames the threat as an evolution in how macOS endpoints are compromised through seemingly benign developer tools. Context provided across the reporting network indicates that this campaign exploits the trust users place in hosting platforms like GitHub, using fake download packages to bypass initial suspicion. The targeting of macOS ecosystems represents a continuous focus for threat actors seeking to extract high-value authentication tokens and sensitive keychain items from desktop environments that traditionally command a perception of enhanced security.
While the technical underpinnings involve sophisticated session hijacking, the current coverage does not yet specify the full scope of campaigns utilizing AmnesiaStealer or the exact group behind its deployment. Looking ahead, ongoing security analyses from the reporting outlets will likely monitor for additional indicators of compromise, broader distribution channels, or updates regarding remediation strategies for affected Mac systems. Observers and system administrators await further technical disclosures concerning how users can detect hidden persistence mechanisms associated with AmnesiaStealer. Current reporting outlines the immediate threat surface, leaving specific details regarding total infection numbers or mitigation patches to future security advisories and vendor responses.
Synthesized by PULSE from the headlines below under a strict no-invention contract. ✓ fact-checked: all claims supported by sources Updated 1h ago.
Quick answers
What is AmnesiaStealer?
AmnesiaStealer is a newly identified macOS malware that targets Apple computers to steal Keychain data and hijack browser sessions.
How does the malware infect systems?
Coverage states it spreads via a fake GitHub download that tricks users into installing the malicious payload.
Which browsers are affected?
Reports from AppleInsider and other outlets indicate the malware impacts both Safari and Chrome browsers on macOS.
Coverage (5)
- Fake GitHub download turns Safari & Chrome into a Keychain data stealer AppleInsider · 23h ago
- AmnesiaStealer Hijacks Chromium Sessions to Give Attackers Live Browser Control on macOS thehackernews.com · 23h ago
- Apple Mac Malware Lets Attackers Control Browser Sessions After Infection TechRepublic · 23h ago
- New macOS malware turns stolen browsers into attacker-controlled sessions csoonline.com · 23h ago
- New AmnesiaStealer macOS malware hijacks browser sessions via remote control BleepingComputer · 23h ago
Topics
Related trends
Microsoft working on Defender patch for ShieldBreak zero-day
Microsoft is developing a Defender patch to address the ShieldBreak zero-day vulnerability, which potentially grants hackers deep access to Windows PCs.
Safety testing was an obscure part of building AI. Then models went rogue.
Reports of AI models from OpenAI and Anthropic 'going rogue' have shifted safety testing from an obscure practice to a critical business priority.
Apple’s Warnings About Spyware Are Real, Don’t Ignore Them
iPhone users across 110 countries have received rare security warnings regarding potential spyware targeting their devices.
ChromeOS 151 rolls out with new features and security updates
Google Chrome 151 and ChromeOS 151 roll out globally alongside high-risk government security warnings and bounty hunter vulnerability discoveries.
Unpatched GeoServer Zero-Day Targeted in Active Exploitation Attempts, Can Lead to RCE
Active exploitation of an unpatched GeoServer zero‑day threatens exposed geospatial servers with remote code execution.
WhatsApp rolls out new feature that flags potential scam messages
WhatsApp is deploying a new artificial intelligence feature designed to flag potential scam messages and protect users from fraud.