738 S 9th St, Philadelphia, PA 19147Call/text 215 821-9605
All news
Cybersecurity

AmnesiaStealer Turns Fake Mac Fixes Into Browser Session Theft

A convincing fake Mac fix can steal live browser sessions. Here is how AmnesiaStealer works and the warning signs Mac users should recognize.

August 18, 2026 4 min read
AmnesiaStealer Turns Fake Mac Fixes Into Browser Session Theft

Security researchers are warning Mac users about AmnesiaStealer, a multi-stage information stealer delivered through a counterfeit GitHub download page and a social-engineering method commonly called ClickFix. Jamf's research, published August 13, found that the page instructed visitors to copy and run a Terminal command as if it were a routine fix. The command then asked for the user's macOS password and started a chain that installed Rust-based malware. BleepingComputer reported the campaign on August 16, bringing wider attention to its browser-session theft and remote-control capabilities.

The important detail is that the attack does not begin with a complicated software exploit. It begins by persuading a person to run the attacker's command. Once installed, the malware can target credentials and data from Chromium-based browsers and help an attacker take control of an active browser session. A stolen session can sometimes let a criminal enter an account even when the owner uses a strong password or multifactor authentication, because the browser may already be trusted.

For everyday Mac users, the clearest warning sign is any webpage, popup, CAPTCHA, installer, or support message that tells you to open Terminal, paste a command, and enter your administrator password. Do not follow those instructions. Close the page and obtain software or support directly from the vendor's official website or the Mac App Store. A polished design, GitHub branding, or familiar security language does not prove that a page is legitimate.

If you already ran a suspicious command, disconnect the Mac from the network and avoid signing into more accounts from that machine. From a different trusted device, change important passwords, sign out other account sessions, and review security alerts and recovery information. The affected Mac should be examined before it is used again; also review browser extensions, login items, and recently installed applications. Orange Tech's practical interpretation is simple: treat Terminal commands like executable software. If you did not independently verify the source and understand the command, do not run it.