Reaper malware targets macOS users via Script Editor to steal crypto wallets, browser passwords, and sensitive files.Reaper malware targets macOS users via Script Editor to steal crypto wallets, browser passwords, and sensitive files.

macOS users lose crypto as Reaper stealer bypasses Terminal

2026/06/09 08:46
3분 읽기
이 콘텐츠에 대한 의견이나 우려 사항이 있으시면 [email protected]으로 연락주시기 바랍니다

A new type of Mac malware called Reaper is spreading through fake download pages for apps like WeChat and Miro. Once it gets in, it steals crypto wallet data and saved browser passwords.

It’s a smarter version of an older trick that used to fool people into pasting malicious commands into Terminal. Apple patched that hole in a recent macOS update, but Reaper found a way around it, using a different built-in Apple tool to do the same damage.

Script Editor replaces Terminal as the malware surface

The fake download sites trigger Script Editor through an AppleScript applescript:// URL.

The malicious code is invisible. Attackers hide it using ASCII art and whitespace. If a user clicks the play button in the Script Editor, they unknowingly run hidden commands.

Script Editor is preinstalled with every Mac computer. Most people don’t relate to viruses.

Typosquatted domains and fake Apple updates build trust

The attack begins on fake domains that look legitimate to potential victims. Security researchers discovered infrastructure hosted on typosquatted Microsoft domains, including mlcrosoft[.]co[.]com.

Once the script runs, a fraudulent Apple security update dialog prompts the victim to enter their computer password.

Reaper then checks the system’s keyboard layout.  If the keyboard is configured for the Russian language, the malware stops.  If not, the malware activates a data-theft module modeled on the Atomic macOS Stealer (AMOS).

Reaper malware hijacks Script Editor to drain crypto wallets on macOS.Fake WeChat code opens up in Script Editor. Source: Moonlock.

Crypto wallets, browsers, and documents are all targeted

Reaper goes after desktop crypto applications, including Ledger Live, Trezor Suite, and Exodus. The malware modifies the internal code of crypto wallets to intercept future transactions and redirect funds.

The stealer also harvests saved credentials from Chrome, Firefox, and Edge. It pulls data from browser extensions like 1Password and MetaMask too.

Files with .docx, .pdf, .xlsx, .wallet, and .keys extensions found in Desktop and Documents folders get compressed into 70MB ZIP chunks and uploaded to an external command-and-control server.

For a persistent attack, Reaper installs a backdoor disguised as a Google Software Update directory.

Reaper is the third campaign within about two months to adopt this automated AppleScript approach, according to Moonlock’s analysis.

Microsoft’s Defender Security Research Team documented a related set of campaigns involving fake macOS troubleshooting guides posted to Medium, Craft, and Squarespace, which Cryptopolitan previously reported.

Those campaigns used the same ClickFix approach to deliver AMOS, Macsync, and SHub Stealer through Terminal commands. Genuine wallet apps were deleted and silently swapped for malicious versions, according to Cryptopolitan.

Double-check download links before installing anything new. If a pop-up unexpectedly asks for your Mac password, don’t enter it. A good security tool will catch obfuscated scripts before they cause damage. If a website ever tells you to open Script Editor, close the tab.

If you're reading this, you’re already ahead. Stay there with our newsletter.

Predict & Trade to Win Rewards

Predict & Trade to Win RewardsPredict & Trade to Win Rewards

Guaranteed rewards with $500,000 prize pool

면책 조항: 본 사이트에 재게시된 글들은 공개 플랫폼에서 가져온 것으로 정보 제공 목적으로만 제공됩니다. 이는 반드시 MEXC의 견해를 반영하는 것은 아닙니다. 모든 권리는 원저자에게 있습니다. 제3자의 권리를 침해하는 콘텐츠가 있다고 판단될 경우, [email protected]으로 연락하여 삭제 요청을 해주시기 바랍니다. MEXC는 콘텐츠의 정확성, 완전성 또는 시의적절성에 대해 어떠한 보증도 하지 않으며, 제공된 정보에 기반하여 취해진 어떠한 조치에 대해서도 책임을 지지 않습니다. 본 콘텐츠는 금융, 법률 또는 기타 전문적인 조언을 구성하지 않으며, MEXC의 추천이나 보증으로 간주되어서는 안 됩니다.

RealStocks Now Live

RealStocks Now LiveRealStocks Now Live

Trade real U.S. stock via regulated brokerage