Mac users searching for a trusted system optimization tool are being targeted in a new malware campaign that impersonates the popular macOS utility CleanMyMac. Security researchers warn that a fraudulent website is distributing SHub Stealer, a credential-stealing malware capable of harvesting passwords and compromising cryptocurrency wallets.
The campaign relies heavily on social engineering. Instead of exploiting technical vulnerabilities, attackers convince victims to manually run a malicious command in the macOS Terminal, allowing the malware to install while appearing to be part of a legitimate setup process.