Fake Claude Guide Spreads MacSync Malware That Steals Passwords and Crypto Wallets

Cybersecurity researchers have uncovered MacSync, a new macOS information stealer that tricks users through a fake Claude installation guide promoted via sponsored Google search results. Victims are instructed to paste a malicious Terminal command, unknowingly installing malware instead of the AI application.

Fake Claude Guide Spreads MacSync Malware That Steals Passwords and Crypto WalletsFake Claude Guide Spreads MacSync Malware That Steals Passwords and Crypto Wallets

Once executed, MacSync steals saved passwords, browser cookies, Keychain data, SSH and cloud credentials, Telegram sessions, and cryptocurrency wallet information. It also installs a remote access tool (RAT), captures screenshots, and targets popular crypto wallet applications by replacing them with trojanized versions designed to steal recovery seed phrases.

Security experts recommend downloading software only from official websites, avoiding Terminal commands from online guides or AI conversations, reviewing unexpected Full Disk Access requests, and monitoring systems for suspicious activity. Organizations should also rotate compromised credentials and isolate affected devices immediately.


NPAV Z Security – Advanced protection against emerging cyber threats and malicious downloads.