SHub Reaper macOS infostealer variant
Malware Activity
Summary
Hide ▲
Show ▼
The SHub Reaper macOS infostealer now uses AppleScript and a fake Apple security update lure to infect Macs, raising the risk of credential theft and remote access. It steals browser data, crypto wallet information, and sensitive files from compromised systems while hiding its payload behind a malicious installer flow. The malware also installs LaunchAgent persistence, which can keep attacker access alive after execution.
Related Happenings
CrashStealer macOS information stealer activity
Malware Activity
H score10
First: 13.07.2026 20:36
Last: 13.07.2026 20:36
Sources 1
About this happening:
CrashStealer is a macOS information-stealing malware that was tracked in May and seen in attacks in early July. It impersonates Apple's crash-reporting tool by...
CrashStealer macOS information stealer activity
Malware ActivityAbout this happening: CrashStealer is a macOS information-stealing malware that was tracked in May and seen in attacks in early July. It impersonates Apple's crash-reporting tool by...
Codemado open-directory operator toolkit leak
Data Leak
H score18
First: 13.07.2026 18:30
Last: 13.07.2026 18:30
Sources 1
About this happening:
A misconfigured Budapest VPS exposed codemado's phishing toolkit, leaking session material and credential artifacts that could enable account hijacking. The readable direc...
Codemado open-directory operator toolkit leak
Data LeakAbout this happening: A misconfigured Budapest VPS exposed codemado's phishing toolkit, leaking session material and credential artifacts that could enable account hijacking. The readable direc...
MemGhost stealth memory injection against OpenClaw personal agents
Technical Analysis
H score23
First: 13.07.2026 16:49
Last: 13.07.2026 16:49
Sources 1
About this happening:
Researchers demonstrated MemGhost, a one-email prompt-injection technique that can plant a persistent false memory in OpenClaw-style personal agents, letting an at...
MemGhost stealth memory injection against OpenClaw personal agents
Technical AnalysisAbout this happening: Researchers demonstrated MemGhost, a one-email prompt-injection technique that can plant a persistent false memory in OpenClaw-style personal agents, letting an at...
Jscrambler 8.14.0 malicious preinstall infostealer release
Malware Activity
H score9
First: 11.07.2026 20:59
Last: 11.07.2026 20:59
Sources 1
About this happening:
The jscrambler 8.14.0 npm release now ships a malicious preinstall hook that runs a Rust infostealer during install, putting developer and CI secrets at risk on ...
Jscrambler 8.14.0 malicious preinstall infostealer release
Malware ActivityAbout this happening: The jscrambler 8.14.0 npm release now ships a malicious preinstall hook that runs a Rust infostealer during install, putting developer and CI secrets at risk on ...
QuimaRAT cross-platform Java MaaS remote access trojan
Malware Activity
H score29
First: 06.07.2026 11:13
Last: 06.07.2026 11:13
Sources 1
About this happening:
A new QuimaRAT MaaS offering expands cross-platform malware risk by packaging a modular Java-based RAT for Windows, Linux, and macOS. The activity matters because...
QuimaRAT cross-platform Java MaaS remote access trojan
Malware ActivityAbout this happening: A new QuimaRAT MaaS offering expands cross-platform malware risk by packaging a modular Java-based RAT for Windows, Linux, and macOS. The activity matters because...
Timeline
-
19.05.2026 00:42 2 articles · 1mo ago
SentinelOne identifies SHub Reaper macOS infostealer
Initial DisclosureSentinelOne identified Reaper, a new SHub macOS infostealer variant that uses an applescript:// URL scheme to open Script Editor with malicious AppleScript, shows a fake Apple security update referencing XProtectRemediator, steals browser data and crypto wallets, targets iCloud, Telegram, and developer files, grabs sensitive files from Desktop and Documents, installs LaunchAgent persistence, and can extend access with remote payload execution; the lure uses fake WeChat and Miro installers and the malware exits on systems with Russian keyboard/input.
Show sources
- SHub macOS infostealer variant spoofs Apple security updates — www.bleepingcomputer.com — 19.05.2026 00:42
- SHub macOS infostealer variant spoofs Apple security updates — www.bleepingcomputer.com — 19.05.2026 00:42