ClickFix on macOS: Blockchain-Powered Infostealer Hidden Inside Compromised Websites
July 16, 2026 · LevelBlue SpiderLabs · Severity: LOW
A new macOS infostealer malware dubbed "ClickFix" is being distributed through compromised legitimate small business websites, according to LevelBlue SpiderLabs. The attack begins when users encounter a fake Cloudflare verification prompt asking them to paste and execute a malicious Terminal command. This command downloads and runs a Python script that installs a blockchain-powered infostealer capable of harvesting sensitive data like passwords, browser histories, and cryptocurrency wallets. The malware leverages blockchain technology for command-and-control communication, making it harder to detect and shut down. macOS users who encounter these fake verification prompts on seemingly legitimate websites are at risk. This attack is particularly concerning because it exploits users' familiarity with Cloudflare security checks to trick them into manually installing malware, bypassing traditional security measures. The campaign highlights the growing sophistication of social engineering attacks targeting macOS systems.
You're browsing a legitimate small business website. Before the page loads, a familiar Cloudflare box appears: "Verify you are human." It asks you to open Terminal, paste a code, and press Enter. You've seen this before. You follow the steps. The page loads normally.
Key Takeaways
- Attackers use fake Cloudflare verification prompts to trick users.
- Users are instructed to paste malicious code into macOS Terminal.
- The malware is a blockchain-powered infostealer hidden on compromised websites.