HomeinetMicrosoft warns about Python Infostealers targeting macOS

Microsoft warns of Python Infostealers targeting macOS

Microsoft has warned that information theft attacks are “expanding rapidly” beyond Windows, targeting Apple macOS environments, leveraging cross-platform languages ​​like Python and abusing trusted platforms for large-scale distribution.

See also: PyPI: Fake Python spellchecker packages delivered RAT malware

Python

The tech company's Defender Security Research team observed infostealer campaigns targeting macOS, using social engineering techniques like ClickFix since late 2025 to distribute disk image (DMG) installers that deploy malware families like Atomic macOS Stealer (AMOS) , MacSync , and DigitStealer .

The campaigns use techniques such as fileless execution, native macOS utilities, and AppleScript automation to facilitate data theft, including browser credentials, session data, iCloud Keychain, and developer secrets.

These attacks often begin with a malicious ad, usually served through Google Ads, which redirects users searching for tools like DynamicLake and artificial intelligence (AI) tools to fake websites using ClickFix bait, tricking them into infecting their own machines with malware.

See also: Malicious PyPI package mimics SymPy and installs XMRig Miner

CPython vulnerability

One such stealer is PXA Stealer, associated with Vietnamese-speaking threat actors, capable of collecting login credentials, financial information, and browser data. Microsoft detected two PXA Stealer campaigns in October 2025 and December 2025 that used phishing emails for initial access.

The attack chains included the use of registry Run keys or scheduled tasks for persistence and Telegram for command and control communications and data extraction.

Additionally, malicious actors have been observed using popular messaging apps like WhatsApp to distribute malware like Eternidade Stealer and gain access to financial and cryptocurrency accounts. Details of the campaign were publicly documented by LevelBlue/Trustwave in November 2025.

Other attacks related to infostealers have revolved around fake PDF editors like Crystal PDF, distributed through malicious ads and search engine optimization (SEO) poisoning via Google Ads to deploy a Windows-based stealer that secretly collects cookies, session data, and credential caches from Mozilla Firefox and Chrome browsers.

See also: Infected Python libraries in Hugging Face models

Microsoft warns of Python Infostealers targeting macOS

To address the threat posed by infostealers, organizations are advised to educate users about social engineering attacks such as malicious ad redirect chains, fake installers, and ClickFix-style copy-paste prompts. It is also recommended to monitor suspicious activity in Terminal and iCloud Keychain access, as well as inspect network output for POST requests to newly registered or suspicious domains.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS