MacSync macOS Stealer Uses Fake Claude Guide to Steal Passwords and Crypto Wallets
Cybersecurity researchers have uncovered MacSync, a new macOS information stealer that tricks users through a fake Claude installation guide promoted via sponsored Google search results. Victims are instructed to paste a malicious Terminal command, unknowingly installing malware instead of the AI application.


Once executed, MacSync steals saved passwords, browser cookies, Keychain data, SSH and cloud credentials, Telegram sessions, and cryptocurrency wallet information. It also installs a remote access tool (RAT), captures screenshots, and targets popular crypto wallet applications by replacing them with trojanized versions designed to steal recovery seed phrases.
Security experts recommend downloading software only from official websites, avoiding Terminal commands from online guides or AI conversations, reviewing unexpected Full Disk Access requests, and monitoring systems for suspicious activity. Organizations should also rotate compromised credentials and isolate affected devices immediately.
NPAV Z Security – Advanced protection against emerging cyber threats and malicious downloads.