
Security researchers at Jamf have discovered a new macOS malware called AmnesiaStealer that is more dangerous than a typical infostealer. Beyond collecting passwords, browser cookies, Apple Notes, keychain data, and cryptocurrency wallets, the malware includes a “stream module” that lets the attacker take live, remote control of the victim’s web browser — navigating sites, clicking buttons, and interacting with authenticated sessions in real time, all while the victim is unaware. It does this by duplicating the browser’s profile (including its login state) into a hidden, headless browser instance, then connecting the attacker to that session over a WebSocket channel with a live 3fps screencast. In effect, once infected, an attacker can log into your bank, email, or crypto exchange using your existing session — no password prompt required.
The malware spreads through ClickFix attacks: victims are tricked into visiting a fake GitHub download page, which prompts them to run a shell command that downloads and executes the malware. Jamf found that AmnesiaStealer reused distribution templates previously seen with the Atomic and MacSync stealers, suggesting shared infrastructure. The malware targets 16 Chromium-based browsers including Chrome, Edge, Brave, Arc, Opera, and Vivaldi on macOS.
How to check if you’re affected
Affected devices are any macOS computers running Chromium-based browsers (Chrome, Edge, Brave, Arc, Opera, Vivaldi) where the user was recently prompted to paste and run a terminal command by a website claiming to “fix” a download or display issue — that is the ClickFix delivery vector. If you ran such a command in the past few weeks, scan your Mac with Malwarebytes or run the free Jamf Protect detection tool. Indicators of compromise (IoCs) from Jamf’s analysis are available in their full report.
