A sophisticated cyberattack is exploiting GitHub Pages to distribute the notorious Atomic stealer to macOS users.
The perpetrators of this operation use Search Engine Optimization (SEO) techniques to place malicious repositories at the top of search results on major platforms, such as Google and Bing, targeting users looking for legitimate software from technology companies, financial institutions, and password management services.
See also: Apple fixes vulnerability (backports) on old devices

The campaign demonstrates a multi-layered approach, where cybercriminals create fake GitHub repositories that pretend to be official software distributors. When victims search for specific applications, the “poisoned” search results redirect them to malicious GitHub Pages hosting what appear to be legitimate software installers.
LastPass 's Threat Intelligence, Mitigation, and Escalation (TIME) team identified this threat after discovering two fake repositories specifically targeting their customers, both created by user “ modhopmduck476 ” on September 16, 2025.
The cyberattack begins when victims encounter malicious GitHub Pages through poisoned SEO search results. These repositories contain misleading “Install [Company] on MacBook” links that redirect users to secondary staging sites. In the case of LastPass, victims are redirected to hxxps://ahoastock825[.]github[.]io/.github/lastpass, which then forwards them to macprograms-pro[.]com/mac-git-2-download.html.
See also: Apple's 'Repair Assistant' tool comes to macOS Tahoe

The secondary website instructs users to run a terminal command that makes a CURL request to a base64- encoded URL . This encoded URL resolves to bonoud[.]com/get3/install.sh , which downloads the malicious payload disguised as a system “ Update ” to the temporary directory. The downloaded file is actually the Atomic stealer malware, also known as AMOS malware, which has been active in cybercriminal circles since April 2023.
Atomic Stealer represents a sophisticated information theft threat specifically designed for macOS environments. The malware is capable of collecting sensitive data, including passwords, browser cookies, cryptocurrency wallet information, and system credentials. Once installed, it establishes persistence on the infected system and communicates with command and control (C2) servers to extract the stolen data.
The attackers have demonstrated operational resilience by creating multiple GitHub usernames to circumvent takedown attempts. This distributed approach allows them to maintain their malicious infrastructure even when individual repositories are reported and removed. The scope of the campaign extends beyond LastPass, with security researchers identifying similar attacks targeting various technology companies and financial institutions using identical tactics and techniques (TTPs).
See also: Apple vulnerability: PoC Exploit released for zero-day bug

LastPass has successfully coordinated the removal of detected malicious repositories and continues to monitor for additional threats. The company advises macOS users to be cautious when downloading software via search results and always verify the authenticity of repositories before executing terminal commands or installing applications from unofficial sources.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
