The SHub “Reaper” macOS infostealer campaign shows how attackers are rapidly adapting to platform security improvements. Instead of relying only on older ClickFix-style Terminal tricks, this variant abuses the applescript:// URL scheme to open Script Editor with malicious AppleScript, then displays a fake Apple security update prompt referencing XProtectRemediator. This is especially dangerous because it uses familiar Apple security language to gain user trust while silently downloading and executing the payload.
The malware’s ability to steal browser data, password manager and crypto wallet extension data, iCloud information, Telegram sessions, developer configuration files, and sensitive documents makes it a serious risk for both individuals and businesses. Organizations using macOS devices should monitor suspicious Script Editor activity, unexpected LaunchAgents, fake updater processes, and abnormal outbound traffic after script execution. macOS is not magically immune to malware; attackers simply learned that social engineering plus trusted-looking Apple prompts works disturbingly well, because apparently even “security update” can now mean “please install my backdoor.”
A new variant of the 'SHub' macOS infostealer uses AppleScript to show a fake security update message and installs a backdoor. [...]
Source: SHub macOS infostealer variant spoofs Apple security updates via Bleeping Computer — published 18 May 2026.
Was this article helpful?
Your feedback helps us improve the knowledge base.