Our team recently published 2026 #macOS malware predictions: supply-chain + AI/workflow (MCP) abuse, signed/notarized stealth & multi-stage loaders, Macs as proxy infrastructure, and “upmarket” infostealers.
Give it a read! 👇
📜 New in our mid-2026 macOS threat report: 20% of malware carried valid Apple Developer certs, ClickFix drove half of initial access, and fake AI-tool installers (Claude, ChatGPT, Codex) are now a top disguise.
#MacOS is no longer the safe bet.
Read it 👉
1/ New #macOS bash dropper - 0 hits on VT. Shared by @malwrhunterteam.
Self-deletes on launch. Delivers a binary from weekly-up[.]online while pushing a fake Zoom, Teams, or SystemApp as cover.
Might be related to Contagious Interview, however no strong confirmation yet. 🧵
A recent surge in the #Odyssey stealer on #macOS has hit 100+ countries.
What this variant does:
- Harvests passwords, cookies & autofill from Chrome, Brave, Edge, Vivaldi, Opera, Arc, Firefox/Waterfox
- Steals wallet files from 16+ crypto apps (Electrum, Exodus, Ledger Live,
1/ New #macOS (crossplatform) sample: a full-featured remote access trojan masquerading as MicrosoftSystem64 and using #huggingface legitimate infrastructure for its C2 activities. JavaScript payload + RAT inside a Mach-O binary. Findings below 👇