# New AmnesiaStealer macOS malware hijacks browser sessions via remote control

> **Open Intelligence Dossier** · First detected: 2026-08-17 12:07 UTC · Category: Technology

## Executive Summary
A new macOS malware named AmnesiaStealer allows attackers to remotely control browser sessions and steal Keychain data via fake GitHub downloads.

## Intelligence Brief
A new security threat identified as AmnesiaStealer is targeting macOS users by hijacking browser sessions. According to reports from BleepingComputer, the malware grants attackers remote control over browser sessions on infected systems. The infection process begins when users engage with fake GitHub downloads, which then turn web browsers such as Safari and Google Chrome into tools for stealing sensitive Keychain data. This mechanism allows the attackers to maintain live control over the user&amp;#039;s browsing activity rather than simply stealing static files. Multiple cybersecurity outlets are tracking the development of this threat.


BleepingComputer, thehackernews.com, and CSO Online emphasize the malware&amp;#039;s ability to turn stolen browsers into attacker-controlled sessions. TechRepublic further highlights that the malware allows attackers to control browser sessions specifically after the initial infection has occurred. Meanwhile, AppleInsider focuses on the delivery method, noting that the fake GitHub downloads are the primary vector used to compromise Safari and Chrome to access the system&amp;#039;s Keychain data. This trend is significant because it shifts the focus from traditional data exfiltration to active session hijacking on the macOS platform. By leveraging the trust associated with GitHub downloads, the attackers can bypass user caution to install AmnesiaStealer.


Once the malware is active, the ability to hijack Chromium-based sessions and Safari provides the attackers with a direct window into the user&amp;#039;s authenticated accounts and stored credentials within the Apple Keychain, increasing the potential for unauthorized access to private accounts. Future monitoring will likely focus on the distribution points of these fake GitHub downloads and the specific technical methods AmnesiaStealer uses to maintain remote control. Based on the coverage from the five reporting outlets, the primary areas of concern remain the vulnerability of Chrome and Safari sessions and the continued risk of social engineering via trusted developer platforms. Users are currently warned about the risks associated with downloads that masquerade as legitimate GitHub projects to avoid Keychain compromise.

## Multi-Source Evidence Table
| Source Outlet | Headline | Verification URL |
|---|---|---|
| AppleInsider | Fake GitHub download turns Safari & Chrome into a Keychain data stealer | [Source Link](https://news.google.com/rss/articles/CBMisgFBVV95cUxQUDBRSXoxaU5ycC1uMjBDa0E4Sk5mWFM4TWduX19GUk9RUWZhT3lPb1BjbWVLV2dFVUs4eFprekpRdjZSWXhMQlpGZWhkYmxIUDJPR2ZqWURNNm84N2Jzd0NBaDA5cTNMUTJDU2doRXNiZWgxaDVNWmItdVJjdUtSRzNvaXdBb19Sand6Nk51dTlPQVE4UjFVMzJSMUtsN0VsU3FXTW5CTmhnSXZBLXFjeEFB?oc=5) |
| thehackernews.com | AmnesiaStealer Hijacks Chromium Sessions to Give Attackers Live Browser Control on macOS | [Source Link](https://news.google.com/rss/articles/CBMiekFVX3lxTFBuVE81c1RiZ1g2ZlR0Rk9jTjFiNU5FaXpqV3R3djRBYnNOek5QNzMxVU4zR1IwQUk2ZnA1SUFvX1dFNEVqaUxIbXo2RnVrZERIQnJJamhRMUE5UXZMdEt6RUFOSWQ1U05hazRqQzNqdWpCbnl3Um42T253?oc=5) |
| TechRepublic | Apple Mac Malware Lets Attackers Control Browser Sessions After Infection | [Source Link](https://news.google.com/rss/articles/CBMieEFVX3lxTE5SUFlrYmRJMEFDdWJTMlpIT0F1V2NZSTlTcUdFMUxtRGg5WDBqdlFWMTVVbDBrR3RTdUpwM2NSVjh1SXVoWHg0ZXFnTHBXSXBSU2FZQVdrYzA2SkV4MjZhMU5mclFvZlQ3NmRmZUR0LVFNLVFQc0Z1LQ?oc=5) |
| csoonline.com | New macOS malware turns stolen browsers into attacker-controlled sessions | [Source Link](https://news.google.com/rss/articles/CBMivAFBVV95cUxPNHUybEpOOGJjc0pxa2JqMzRwTXB2Tk9ENHh5Y3ZZTTZTcmlVZGlnWC1fdE1CcGFEVkxHSklIeDYyZVBud1dWbXhxd01saUxGbGlmOGVTSXVvVkNyMVlvRC1aZW5OLVNwVUthcG4wLTg4QnJsUkxwRmJvcHNxR0s3Y3l4OG4yTHlDcXR0U0MwSW9DbHFjYUYwdjRWZ2xISjVIUjBXdmd6S2dkX2hYQVQzQTlOUDlkNmVwLVphag?oc=5) |
| BleepingComputer | New AmnesiaStealer macOS malware hijacks browser sessions via remote control | [Source Link](https://news.google.com/rss/articles/CBMiwgFBVV95cUxOekpFUkRnWE1fOVJlTTlxckE2bEpweDFOUUdBbWNhWWZzSm01a2VXdjFHT3M5UDZBUWZKcTVoNF8wblo5LXJCTGVYME9Ud1FSV1FXN0NHTURMZVJ5OHpiVFZJNEVjLTBXYzRINmVkek1tMy1qckhGaV8wNlBiOVFEak82b09kblJsZ2RSUzJndWhsVUJ5RWJDVE5kX0NqdTNjMkphOVNRTTZIaElsdi1udE1JdS1FZ1J3MDJDd2hjNFIzQdIBxwFBVV95cUxNOFRfaWFSVE9iaTM3VnMtQngtUGRKNmtpQ2Zac1FER200YVdMMWVTWGFHVFBNRXlqNjdYMi1GSTBuUktaRnhwN09nV29Bd1pNMkVnT1hGcGdHODVmZzlWbEw2bEtHWXEzWHVSNHVHTmRfV1lHSi1aUDByWVUzQWxmbHlyeE4yQWtFNFhLX3g5S1c) |

---
*Canonical Source: https://pulse.byoviral.com/trend/2026-08-17/new-amnesiastealer-macos-malware-hijacks-browser-sessions-via-remote-control*
