<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Mac-Malware on HackingPassion.com : root@HackingPassion.com-[~]</title><link>https://hackingpassion.com/tags/mac-malware/</link><description>Recent content in Mac-Malware on HackingPassion.com : root@HackingPassion.com-[~]</description><generator>Hugo</generator><language>en</language><lastBuildDate>Tue, 12 May 2026 11:37:35 +0200</lastBuildDate><atom:link href="https://hackingpassion.com/tags/mac-malware/index.xml" rel="self" type="application/rss+xml"/><item><title>MacSync Malware Spreads Through Claude.ai and Replaces Your Crypto Wallet Apps</title><link>https://hackingpassion.com/macsync-clickfix-claude/</link><pubDate>Tue, 12 May 2026 11:37:35 +0200</pubDate><guid>https://hackingpassion.com/macsync-clickfix-claude/</guid><description>&lt;p>&lt;strong>MacSync&lt;/strong> is spreading through &lt;strong>Google ads&lt;/strong> that lead directly to &lt;strong>claude.ai&lt;/strong>. The installation guide there was written by Claude itself. One Terminal command and the malware is running, your credentials are gone, and your crypto wallet applications have been replaced.&lt;/p>
&lt;p>Security researcher &lt;strong>Berk Albayrak&lt;/strong> spotted an active version of this campaign on &lt;strong>May 9, 2026&lt;/strong> and posted his findings on X. Researcher &lt;strong>g0njxa&lt;/strong> also published findings on X tracing the campaign infrastructure. &lt;strong>BleepingComputer&lt;/strong> independently confirmed a second variant running on completely separate infrastructure.&lt;/p></description></item></channel></rss>