Free MacOS malware for everyone! Hurry up before Google patches it!

On Monday (December, 15th, 2025) @whitneyfat sent me a DM on X about a website doing ClickFix targeting MacOS. When I visited the website I got this beauty:

I said, "Oh my God, is this the Click Fix and/or Masquerade ON MACOS?!". I was excited. However, I am now disappointed.

The website says you need to run this script to make your Mac fast, or something, I don't know, some dumb bullshit:

The final echo is BASE64 encoded string.

Okay, so now we CURL that bitch and get some more obfuscated bullshit.

Now we (unironically) have ChatGPT make me a slop script to decode this fucking thing so I don't have to work on it

ChatGPT slop script gives us this ugly son-of-a-bitch

Unfortunately, the C2 is dead. Trying to use the API keys in the script returns 404. Fortunately, @0x_b0mb3r messages me and said he's found something similar by Google dorks.

This dork gave me over 9000 dumb fucking sites trying to deliver malware.

As you can see, this is totally normal and not malware (it's malware).

When you click "Download Zip" it directs you to a bunch of different things. I don't feel like documenting the redirects. The redirects though determine your browser agent and stuff. If you're on Windows you get this:

Thanks to @saggy_bean I learned it delivers this on iPhones:

I haven't poked that with a stick more.Anyway, on Linux it tries to get you to install a Mozilla extension. I haven't looked at this either.

On MacOS this website redirects to here:

As you can see, it's the same website layout from earlier, except this time it's a different URL and different API keys.

Repeating the same steps as above, and using our handy-dandy ChatGPT slop script, we get this:

File hash:

VirusTotal link: https://www.virustotal.com/gui/file/e525bd0949ef2963b249b2fe21b5ff575da3dd8a6000280c67dd718e22a59680

Windows Payload:

"Password" provided from website: 8780

VirusTotal link: https://www.virustotal.com/gui/file/de7a6fca548b3d28776a0b6ee9e6f9a302ebe02ab6e3c1278b8c06b920bcf6d3

Surprise: it's an APP ASAR slop thingy. It decompresses to a really big file. I don't have time to keep reversing this. Good luck

Last updated