Threat actors are leveraging fake software websites to distribute Reaper, a significantly updated version of the macOS SHub Stealer.
By impersonating popular applications like WeChat and Miro, cybercriminals are successfully deploying this malware to unsuspecting Mac users.
The campaign utilizes a streamlined variation of the ClickFix technique that automates malicious code execution, making the attack much harder to spot.
SHub Stealer Targets Wallets
Traditional ClickFix attacks rely on social engineering to trick victims into manually copying and pasting malicious scripts into the macOS Terminal.
This new campaign takes a dangerous shortcut by directly launching the native Script Editor app, which is preloaded with malicious code.
When users click the native “Play” button in the Script Editor, the infection chain begins automatically.

This marks the third time in two months that security researchers have observed threat actors bypassing manual Terminal interactions in favor of this automated, highly effective approach.
To build credibility, attackers heavily spoof major tech brands to disguise their infrastructure. They host their payloads on typo-squatted domains like mlcrosoft[.]co[.]com and disguise them as legitimate Apple security updates.

The malware even establishes persistence by hiding a backdoor within a fake Google Software Update directory.
Threat actors actively exploit the technical complexity of native macOS tools, banking on the fact that most users trust default applications like the Script Editor.
Once the initial payload executes, Reaper immediately checks the system’s keyboard configuration. If the Mac uses a Russian layout, the malware automatically halts execution to avoid targeting regional systems.

For all other users, Reaper triggers a fake system password prompt to escalate privileges and access restricted local resources.
Rather than simply swapping out crypto wallets with fake versions, Reaper modifies the core code of your legitimate desktop wallet applications to siphon funds.
After compiling the stolen data, the malware compresses it. It uses the native macOS curl command to exfiltrate the payload to an attacker-controlled command-and-control server.
Finally, Reaper ensures it maintains access to the compromised machine.
It drops an encoded bash script and registers it as a LaunchAgent property list to run silently in the background. Protecting your system from these advanced stealers requires a layered defense strategy.
Using dedicated macOS security tools, such as Moonlock, can help detect hidden threats in real time, including malicious Terminal scripts.
Keep your crypto assets in offline cold wallets when possible, and remember that legitimate software installations will never randomly prompt for your system password after initial setup.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.