Find notable cyber news and cases, enriched with sources, timelines, and signals.

SHub Reaper macOS infostealer variant

Malware Activity
First reported
Last updated
Happening score
H score 23
1 unique sources, 1 articles

Summary

Hide ▲

The SHub Reaper macOS infostealer now uses AppleScript and a fake Apple security update lure to infect Macs, raising the risk of credential theft and remote access. It steals browser data, crypto wallet information, and sensitive files from compromised systems while hiding its payload behind a malicious installer flow. The malware also installs LaunchAgent persistence, which can keep attacker access alive after execution.

Related Happenings

CrashStealer macOS information stealer activity

Malware Activity
H score10 First: 13.07.2026 20:36 Last: 13.07.2026 20:36 Sources 1

About this happening: CrashStealer is a macOS information-stealing malware that was tracked in May and seen in attacks in early July. It impersonates Apple's crash-reporting tool by...

Codemado open-directory operator toolkit leak

Data Leak
H score18 First: 13.07.2026 18:30 Last: 13.07.2026 18:30 Sources 1

About this happening: A misconfigured Budapest VPS exposed codemado's phishing toolkit, leaking session material and credential artifacts that could enable account hijacking. The readable direc...

MemGhost stealth memory injection against OpenClaw personal agents

Technical Analysis
H score23 First: 13.07.2026 16:49 Last: 13.07.2026 16:49 Sources 1

About this happening: Researchers demonstrated MemGhost, a one-email prompt-injection technique that can plant a persistent false memory in OpenClaw-style personal agents, letting an at...

Jscrambler 8.14.0 malicious preinstall infostealer release

Malware Activity
H score9 First: 11.07.2026 20:59 Last: 11.07.2026 20:59 Sources 1

About this happening: The jscrambler 8.14.0 npm release now ships a malicious preinstall hook that runs a Rust infostealer during install, putting developer and CI secrets at risk on ...

QuimaRAT cross-platform Java MaaS remote access trojan

Malware Activity
H score29 First: 06.07.2026 11:13 Last: 06.07.2026 11:13 Sources 1

About this happening: A new QuimaRAT MaaS offering expands cross-platform malware risk by packaging a modular Java-based RAT for Windows, Linux, and macOS. The activity matters because...

Timeline

  1. 19.05.2026 00:42 2 articles · 1mo ago

    SentinelOne identifies SHub Reaper macOS infostealer

    Initial Disclosure

    SentinelOne identified Reaper, a new SHub macOS infostealer variant that uses an applescript:// URL scheme to open Script Editor with malicious AppleScript, shows a fake Apple security update referencing XProtectRemediator, steals browser data and crypto wallets, targets iCloud, Telegram, and developer files, grabs sensitive files from Desktop and Documents, installs LaunchAgent persistence, and can extend access with remote payload execution; the lure uses fake WeChat and Miro installers and the malware exits on systems with Russian keyboard/input.

    Show sources