GoPlus: "Infiniti Stealer" Malware Targets Mac Users to Steal Crypto Assets

PANews, March 30 — GoPlus Security reports that a newly identified malware strain dubbed Infiniti Stealer is targeting macOS users, luring them to manually paste and run malicious commands through a fake Cloudflare CAPTCHA page. The initial script strips macOS quarantine flags, drops a second-stage payload to /tmp, and executes it silently in the background. The final stage is a Python-based credential stealer compiled with Nuitka to improve evasion. GoPlus says the malware is capable of exfiltrating sensitive data, including Chromium and Firefox browser credentials, macOS Keychain information, cryptocurrency wallets, and developer .env files. It also employs stealth tactics such as sandbox detection and delayed execution. GoPlus advises users to avoid unknown links and unverified software installations. If compromise is suspected, users should immediately disconnect the device and reset critical credentials from a clean system.