A routine ‘verify you are human’ page should not prompt you to open Terminal, the Mac app used for running commands. Yet, this is how a new malware attack infiltrates Macs. The page instructs you to copy and paste a command into Terminal. A progress bar then displays while the command discreetly downloads malicious software.
Subsequently, a password box may appear, resembling a normal macOS request. Canceling the request can cause the malware to reappear, repeatedly closing Finder, your browser, and other apps. Your Mac may become difficult to use until you input your login password.
What is ClickLock Mac Malware?
ClickLock is a malicious script aimed at stealing personal information from Macs. It seeks saved passwords, browser data, and cryptocurrency wallet files. Additionally, it installs a hidden tool that allows attackers to remotely control your computer later.
Researchers from cybersecurity company Group-IB identified the malware on VirusTotal, a service that scans files for threats. Someone uploaded it on June 9, 2026, but no security tools recognized it at the time of the report. Group-IB states the campaign has targeted at least 100 systems across 33 countries since May.
How ClickLock Initiates an Attack
Group-IB suggests ClickLock employs a strategy known as ClickFix. This involves displaying a misleading error or verification request. The page provides a command purported to fix the issue. Upon entering the command into Terminal, an animated progress bar reassures with messages about browser checks and human verification.
The script conceals keyboard interruptions and hides the Terminal cursor while downloading malicious components. Although researchers have not confirmed exact landing pages, the design indicates a ClickFix-style lure.
The Password Trap
The malware then displays a fake macOS password window, featuring the Apple icon and your real username.
After entering a password, ClickLock verifies it against your Mac. If correct, it records and transmits the password to the attacker via Telegram. An incorrect password prompts another request. Cancelling leads to the installation of two LaunchAgents. These LaunchAgents reacquire the password-stealing components at your next login.
ClickLock’s Tactics
With a real macOS Keychain prompt triggered, ClickLock targets Chrome’s Safe Storage key, potentially decrypting sensitive information. The script suppresses macOS NotificationCenter, disguising the attack further.
ClickLock scans information across various browsers, including Chrome, Firefox, and Safari. It searches for stored usernames, passwords, cookies, and more. The malware also targets macOS Keychain, Terminal command histories, and other sensitive data. It compiles this information into a ZIP archive transmitted through Telegram’s Bot API.
Evading Detection
The initial ClickLock script was detected by none on VirusTotal. Security vendors are likely updating tools as the threat evolves. Some components execute without saving typical files and delete themselves after exfiltrating data.
Staying Safe from ClickLock
To avoid ClickLock’s trap:
- Exit sites directing you to Terminal.
- Understand commands before executing them.
- Question unexpected password requests.
- Maintain current macOS security protections.
- Use strong antivirus software.
- Shut down your Mac if apps start closing unexpectedly.
Upon noticing suspicious behavior, shut your Mac down. Restart in Safe Mode to prevent further damage. Secure your accounts on another device, change passwords, and remove unrecognized devices from your Apple Account.
ClickLock capitalizes on the risky moment of pasting a Terminal command. Recognize that legitimate verification never requires this step. If your Mac becomes dysfunctional, opt for a complete shutdown and seek professional help to remove the backdoor.

Beware Fake Party Invitations: Tips to Protect Your Computer
Compensation Available in Labcorp Data Breach Settlement
Transforming Healthcare with AI: A Human-Centric Approach
White House to Exempt Some AI Systems from Government Vetting
SpaceX Reports Significant Loss After Initial Public Offering
Understanding the Rise of AI-Powered Phishing Scams