PULSE the living trend engine
🤖 Open Intelligence Dossier available for AI agents & citation View Markdown (.md) →
◼ Archived Technology 🔮 PULSE predicts: fades by tomorrow — graded ✓ correct

New AmnesiaStealer macOS malware hijacks browser sessions via remote control

A new macOS malware named AmnesiaStealer allows attackers to remotely control browser sessions and steal Keychain data via fake GitHub downloads.

5sources
5articles
3velocity
+0%since first seen
48d agofirst detected

Velocity

How fast coverage is spreading — measured hourly from article rate × source diversity. How this works →

📍 How it ended

New AmnesiaStealer macOS malware emerged, utilizing a fake GitHub download to hijack Safari and Chrome browsers for Keychain data theft. The malware allowed attackers to maintain live remote control over infected Chromium sessions.

Coverage of the trend quieted without a definitive conclusion regarding its broader resolution.

Epilogue added 40d ago, after coverage quieted.

The brief

A new security threat identified as AmnesiaStealer is targeting macOS users by hijacking browser sessions. According to reports from BleepingComputer, the malware grants attackers remote control over browser sessions on infected systems. The infection process begins when users engage with fake GitHub downloads, which then turn web browsers such as Safari and Google Chrome into tools for stealing sensitive Keychain data. This mechanism allows the attackers to maintain live control over the user's browsing activity rather than simply stealing static files. Multiple cybersecurity outlets are tracking the development of this threat.

BleepingComputer, thehackernews.com, and CSO Online emphasize the malware's ability to turn stolen browsers into attacker-controlled sessions. TechRepublic further highlights that the malware allows attackers to control browser sessions specifically after the initial infection has occurred. Meanwhile, AppleInsider focuses on the delivery method, noting that the fake GitHub downloads are the primary vector used to compromise Safari and Chrome to access the system's Keychain data. This trend is significant because it shifts the focus from traditional data exfiltration to active session hijacking on the macOS platform. By leveraging the trust associated with GitHub downloads, the attackers can bypass user caution to install AmnesiaStealer.

Once the malware is active, the ability to hijack Chromium-based sessions and Safari provides the attackers with a direct window into the user's authenticated accounts and stored credentials within the Apple Keychain, increasing the potential for unauthorized access to private accounts. Future monitoring will likely focus on the distribution points of these fake GitHub downloads and the specific technical methods AmnesiaStealer uses to maintain remote control. Based on the coverage from the five reporting outlets, the primary areas of concern remain the vulnerability of Chrome and Safari sessions and the continued risk of social engineering via trusted developer platforms. Users are currently warned about the risks associated with downloads that masquerade as legitimate GitHub projects to avoid Keychain compromise.

Synthesized by PULSE from the headlines below under a strict no-invention contract. ✓ fact-checked: all claims supported by sources Updated 46d ago.

Quick answers

What is AmnesiaStealer?

It is a new macOS malware that hijacks browser sessions via remote control and steals Keychain data.

How is the malware distributed?

According to AppleInsider, it is spread through fake GitHub downloads.

Which browsers are affected?

The coverage specifically mentions Safari and Chromium-based browsers, including Google Chrome.

Coverage (5)

Topics

Related trends

\n \n \n \n \n \n \n