A macOS information stealer found on a real-world system is the latest sign that Mac-focused credential theft is becoming a more serious operational threat.
In an Objective-See analysis, guest researcher Pablo Redondo Castro said the sample he found were advertised online through fake software-updates and related to the pesky Atomic macOS Stealer, or AMOS. He also flagged rvdownloads.com as a new indicator defenders should watch.
The malware was built to exfiltrate data and maintain persistence on targeted systems.
According to the Castro, the malware used a curl-to-zsh chain, a command-line shortcut that downloads a remote script using curl and immediately executes it by piping the data directly into the Zsh shell A Zsh shell is an extended Unix shell that interprets the downloaded code as a series of instructions for your computer to follow.
After using the “curl-to-zsh” chain to launch, the malware checks for virtualized environments, displayed a fake system dialog to capture the victim’s password, then pilfers browser logins, cookies, Telegram data, Apple Notes data, Safari secrets, documents, and cryptocurrency wallet information. It also tried to disable security tools and persist through a LaunchAgent disguised as an Apple component.
Part of a Larger macOS Trend
This recent research suggests this is not an isolated Mac oddity. In February, Microsoft said infostealer activity is expanding beyond Windows and that, since late 2025, it has seen campaigns using malicious DMG installers, ClickFix-style prompts, native macOS utilities, and AppleScript automation to steal credentials, session data, keychain secrets, and developer data.
Other recent reports point the same way. Gen Digital warned last week that cracked macOS software moves through a loose supply chain in which every re-upload or repack creates another chance to insert malware. On March 20, LevelBlue’s SpiderLabs described MioLab as a commercialized macOS stealer operation that targets messaging apps, Apple Notes, browser data, and crypto-wallet material.