HomeSecurityMac: New ClickFix attack abuses Script Editor

Mac: New ClickFix attack abuses Script Editor

ClickFix attacks targeting Mac users are evolving, now exploiting the Script Editor instead of the Terminal. This bypasses Apple's recent protections and greatly simplifies the process for attackers. Apple introduced in macOS 26.4 command scanning for pasted input , a measure that limited the previous variant of the attack. But the new technique bypasses this obstacle, making the threat more effective.

Mac Script Editor ClickFix

How the New ClickFix Technique Works Against Mac

According to Jamf , attackers are now using a guided workflow that launches Script Editor directly from the browser (via the applescript:// URL scheme). The Script Editor opens with a pre-filled script that is presented as a storage cleanup tool, misleading users into executing malicious code. Users are initially taken to a fake website that claims their Mac is low on space and provides instructions that appear legitimate. There is also a “ Run ” button.

See also: Beware! Malicious ads target Mac users

Technical Execution and Payload Delivery

The malicious process begins with an obfuscated shell script that decodes a hidden URL and retrieves the payload via curl, executing it directly in memory. A second stage then downloads a Mach-O binary to the /tmp directory, strips out the extended attributes, and launches it. Jamf identifies the payload as a variant of Atomic Stealer, designed to collect sensitive data from the system. This technique reflects a cleaner and more convincing workflow, increasing the likelihood that the user will unwittingly approve the execution of the malicious script.

What It Means for macOS Security

The switch from Terminal to Script Editor exposes a weakness in macOS security controls. Apple has focused on scanning pasted commands in Terminal, but Script Editor remains a system application that can be launched via URL, allowing attackers to execute malicious code with minimal user intervention. The routine nature and familiarity of the macOS environment make this technique particularly dangerous.

Mac: New ClickFix attack abuses Script Editor

Danger Signs and Treatment

Mac users should be aware that no system maintenance or storage management process is initiated from a browser or through Script Editor. Any request to run a script or open a system application from a website should be considered suspicious. Apple provides all maintenance tools through System Preferences and built-in utilities. Scripts initiated from a browser are not part of the normal operation of macOS.

See also: Anthropic: Claude AI uses your Mac when you're away

Detection and Protection

Jamf’s report includes infrastructure associated with the ClickFix campaign, such as the dryvecar[.]com domain and fake cleanup pages, which can be used by security tools to block or detect similar attacks. Recognizing these red flags, combined with updating macOS to the latest version, remains the most effective defense.

Mac: New ClickFix attack abuses Script Editor

Tips for Mac Users

To avoid social engineering attacks via Script Editor, you should never approve the execution of scripts launched from a browser. Dialogs requesting permission for system applications should be treated as suspicious and the process should be stopped before any code is executed. System management and space cleanup should only be performed through official Apple tools.

See also: GhostClaw: Malware for macOS via GitHub

Attackers’ adaptation to macOS protections shows that security is an ongoing battle. Changes in macOS 26.4 have reduced some common attack paths, but future updates will likely be needed to add additional friction to evolving techniques like ClickFix, reminding users of the importance of being informed and vigilant.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS