New AmnesiaStealer macOS malware hijacks browser sessions via remote control
A new macOS malware named AmnesiaStealer allows attackers to remotely control browser sessions and steal Keychain data via fake GitHub downloads.
Velocity
How fast coverage is spreading — measured hourly from article rate × source diversity. How this works →
📍 How it ended
New AmnesiaStealer macOS malware emerged, utilizing a fake GitHub download to hijack Safari and Chrome browsers for Keychain data theft. The malware allowed attackers to maintain live remote control over infected Chromium sessions.
Coverage of the trend quieted without a definitive conclusion regarding its broader resolution.
Epilogue added 40d ago, after coverage quieted.
The brief
A new security threat identified as AmnesiaStealer is targeting macOS users by hijacking browser sessions. According to reports from BleepingComputer, the malware grants attackers remote control over browser sessions on infected systems. The infection process begins when users engage with fake GitHub downloads, which then turn web browsers such as Safari and Google Chrome into tools for stealing sensitive Keychain data. This mechanism allows the attackers to maintain live control over the user's browsing activity rather than simply stealing static files. Multiple cybersecurity outlets are tracking the development of this threat.
BleepingComputer, thehackernews.com, and CSO Online emphasize the malware's ability to turn stolen browsers into attacker-controlled sessions. TechRepublic further highlights that the malware allows attackers to control browser sessions specifically after the initial infection has occurred. Meanwhile, AppleInsider focuses on the delivery method, noting that the fake GitHub downloads are the primary vector used to compromise Safari and Chrome to access the system's Keychain data. This trend is significant because it shifts the focus from traditional data exfiltration to active session hijacking on the macOS platform. By leveraging the trust associated with GitHub downloads, the attackers can bypass user caution to install AmnesiaStealer.
Once the malware is active, the ability to hijack Chromium-based sessions and Safari provides the attackers with a direct window into the user's authenticated accounts and stored credentials within the Apple Keychain, increasing the potential for unauthorized access to private accounts. Future monitoring will likely focus on the distribution points of these fake GitHub downloads and the specific technical methods AmnesiaStealer uses to maintain remote control. Based on the coverage from the five reporting outlets, the primary areas of concern remain the vulnerability of Chrome and Safari sessions and the continued risk of social engineering via trusted developer platforms. Users are currently warned about the risks associated with downloads that masquerade as legitimate GitHub projects to avoid Keychain compromise.
Synthesized by PULSE from the headlines below under a strict no-invention contract. ✓ fact-checked: all claims supported by sources Updated 46d ago.
Quick answers
What is AmnesiaStealer?
It is a new macOS malware that hijacks browser sessions via remote control and steals Keychain data.
How is the malware distributed?
According to AppleInsider, it is spread through fake GitHub downloads.
Which browsers are affected?
The coverage specifically mentions Safari and Chromium-based browsers, including Google Chrome.
Coverage (5)
- Fake GitHub download turns Safari & Chrome into a Keychain data stealer AppleInsider · 49d ago
- AmnesiaStealer Hijacks Chromium Sessions to Give Attackers Live Browser Control on macOS thehackernews.com · 49d ago
- Apple Mac Malware Lets Attackers Control Browser Sessions After Infection TechRepublic · 49d ago
- New macOS malware turns stolen browsers into attacker-controlled sessions csoonline.com · 49d ago
- New AmnesiaStealer macOS malware hijacks browser sessions via remote control BleepingComputer · 49d ago
Topics
Related trends
GitLab warns of critical RCE vulnerability in AI Gateway service
GitLab addresses a critical remote code execution flaw in its AI Gateway service.
Medical records giant Epic pauses product development to fix security bugs that risk patients' data
Medical records giant Epic pauses product development to fix security bugs that risk patients' data.
This new ChatGPT scam tricks you into installing malware
4 news sources are covering this Technology story right now — PULSE is tracking how fast it spreads.
Apple will limit Mac disk access as AI agents ‘substantially’ increase risk
Apple plans to restrict Mac disk access permissions and flag AI requests due to increasing security risks.
A Flaw in ChatGPT’s Mac App Could Have Let Hackers Grab Sensitive Data
A newly reported security flaw in the ChatGPT macOS application could have allowed unauthorized access to sensitive user conversation histories.
Apple says it’s tightening macOS ‘Full Disk Access’ controls due to new risks from AI agents
Apple is restricting macOS 'Full Disk Access' controls as the rise of AI agents creates new security risks for Mac users.