Fake Homebrew Pages Deliver Cuckoo Stealer via ClickFix | macOS Threat Hunting Analysis
hunt.io | research | #supply-chain | #malware | #threat-hunting | #macos | #typosquatting | #homebrew | #cuckoo-stealer | #clickfix | #info-stealer
Summary
Homebrew typosquats delivered Cuckoo Stealer via ClickFix: a first stage stole credentials via dscl authonly prompts, then a macOS infostealer/RAT hitting 20+ wallets and persisting via LaunchAgent.
- Published
- Collected
Skip to content