{"id":7105,"date":"2025-09-22T10:03:27","date_gmt":"2025-09-22T10:03:27","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/09\/22\/massive-cyber-attack-attacking-macos-users-via-github-pages-to-deliver-stealer-malware\/"},"modified":"2025-09-22T10:03:27","modified_gmt":"2025-09-22T10:03:27","slug":"massive-cyber-attack-attacking-macos-users-via-github-pages-to-deliver-stealer-malware","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/09\/22\/massive-cyber-attack-attacking-macos-users-via-github-pages-to-deliver-stealer-malware\/","title":{"rendered":"Massive Cyber-Attack Attacking macOS Users via GitHub Pages to Deliver Stealer Malware"},"content":{"rendered":"<p>    Massive Cyber-Attack Attacking macOS Users via GitHub Pages to Deliver Stealer Malware<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A sophisticated cyber-attack campaign exploiting GitHub Pages to distribute the notorious Atomic stealer malware to macOS users.\u00a0<\/p>\n<p>The threat actors behind this operation are leveraging <a href=\"https:\/\/cybersecuritynews.com\/how-to-protect-your-website-and-maintain-search-engine-rankings\/\" target=\"_blank\" rel=\"noreferrer noopener\">Search Engine Optimization (SEO)<\/a> techniques to position malicious repositories at the top of search results across major platforms, including Google and Bing, targeting users searching for legitimate software from technology companies, financial institutions, and password management services.<\/p>\n<p>The campaign demonstrates a multi-layered approach where cybercriminals create fraudulent <a href=\"https:\/\/cybersecuritynews.com\/23000-github-repositories-targeted\/\" target=\"_blank\" rel=\"noreferrer noopener\">GitHub repositories<\/a> that masquerade as official software distributors.\u00a0<\/p>\n<p>When victims search for specific applications, the poisoned search results redirect them to malicious GitHub Pages hosting what appears to be legitimate software installers.\u00a0<\/p>\n<p>The LastPass Threat Intelligence, Mitigation, and Escalation (TIME) team identified this threat after discovering two fraudulent repositories specifically targeting their customers, both created by the user \u201cmodhopmduck476\u201d on September 16, 2025.<\/p>\n<p><strong>Atomic Stealer Campaign Targets macOS Users<\/strong><\/p>\n<p>The attack chain begins with victims encountering malicious GitHub Pages through <a href=\"https:\/\/cybersecuritynews.com\/weaponized-ai-generated-summaries\/\" target=\"_blank\" rel=\"noreferrer noopener\">SEO-poisoned<\/a> search results.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhe7ruJ2aUdxOqVqQwLPRw1sc4cFyZ4hQTka27gHJ02bi14qEFcQ4869jPqsQpMUPXrMuOY_0j8x0ZEGHSeQkISlO86CE4EQDVU-JUtZdvrIej3DoyIFlRV9VQSI5p2x8NSkIRP9u2PYBBpLDqcNlBfd86bOigyLZFoiXthdHo0MPWvMibkP_2Vk5asj3U4\/s16000\/Screen%2520Capture%2520of%2520SEO-driven%2520Referral.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">SEO-driven Referral to Malicious Software<\/figcaption><\/figure>\n<\/div>\n<p class=\"has-text-align-left\">These repositories contain deceptive \u201cInstall [Company] on MacBook\u201d links that redirect users to secondary staging sites.\u00a0<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full\"><img data-recalc-dims=\"1\" fetchpriority=\"high\" decoding=\"async\" width=\"797\" height=\"857\" src=\"https:\/\/i0.wp.com\/cybersecuritynews.com\/wp-content\/uploads\/2025\/09\/image-121.png?resize=797%2C857&#038;ssl=1\" alt=\"LastPass Impersonation Page\" class=\"wp-image-127330\" srcset=\"https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2025\/09\/image-121.png 797w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2025\/09\/image-121-279x300.png 279w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2025\/09\/image-121-768x826.png 768w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2025\/09\/image-121-391x420.png 391w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2025\/09\/image-121-696x748.png 696w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2025\/09\/image-121-150x161.png 150w\" sizes=\"(max-width: 797px) 100vw, 797px\"><figcaption class=\"wp-element-caption\">LastPass Impersonation Page<\/figcaption><\/figure>\n<\/div>\n<p>In the LastPass case, victims were redirected to hxxps:\/\/ahoastock825[.]github[.]io\/.github\/lastpass, which subsequently forwarded them to macprograms-pro[.]com\/mac-git-2-download.html.<\/p>\n<p>The secondary site instructs users to execute a terminal command that performs a CURL request to a base64-encoded URL.\u00a0<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"945\" height=\"514\" src=\"https:\/\/i0.wp.com\/cybersecuritynews.com\/wp-content\/uploads\/2025\/09\/image-120.png?resize=945%2C514&#038;ssl=1\" alt=\"Secondary site\" class=\"wp-image-127329\" srcset=\"https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2025\/09\/image-120.png 945w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2025\/09\/image-120-300x163.png 300w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2025\/09\/image-120-768x418.png 768w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2025\/09\/image-120-772x420.png 772w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2025\/09\/image-120-696x379.png 696w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2025\/09\/image-120-150x82.png 150w\" sizes=\"(max-width: 945px) 100vw, 945px\"><figcaption class=\"wp-element-caption\">Secondary site<\/figcaption><\/figure>\n<\/div>\n<p>This encoded URL resolves to bonoud[.]com\/get3\/install.sh, which downloads the malicious payload disguised as a system \u201cUpdate\u201d to the temporary directory.\u00a0<\/p>\n<p>The downloaded file is actually the <a href=\"https:\/\/cybersecuritynews.com\/atomic-stealer-disguised-as-cracked-software\/\" target=\"_blank\" rel=\"noreferrer noopener\">Atomic stealer malware<\/a>, also known as AMOS malware, which has been active in cybercriminal circles since April 2023.<\/p>\n<p>Atomic Stealer represents a sophisticated information-stealing threat specifically designed for macOS environments.\u00a0<\/p>\n<p>The malware is capable of harvesting sensitive data, including passwords, browser cookies, cryptocurrency wallet information, and system credentials.\u00a0<\/p>\n<p>Once installed, it establishes persistence on the infected system and communicates with <a href=\"https:\/\/cybersecuritynews.com\/command-and-controlc2-server\/\" target=\"_blank\" rel=\"noreferrer noopener\">command-and-control (C2)<\/a> servers to exfiltrate stolen data.<\/p>\n<p>The threat actors have demonstrated operational resilience by creating multiple GitHub usernames to circumvent takedown efforts.\u00a0<\/p>\n<p>This distributed approach allows them to maintain their malicious infrastructure even when individual repositories are reported and removed.\u00a0<\/p>\n<p>The campaign\u2019s scope extends beyond LastPass, with security researchers identifying similar attacks targeting various technology companies and financial institutions through identical<a href=\"https:\/\/cybersecuritynews.com\/auto-color-linux-backdoor\/\" target=\"_blank\" rel=\"noreferrer noopener\"> tactics and techniques (TTPs)<\/a>.<\/p>\n<p>LastPass has successfully coordinated the takedown of the identified malicious repositories and continues monitoring for additional threats.\u00a0<\/p>\n<p>The company advises macOS users to exercise caution when downloading software through search results and to always verify the authenticity of repositories before executing terminal commands or installing applications from unofficial sources.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/cyber-attack-attacking-macos-users\/\">Massive Cyber-Attack Attacking macOS Users via GitHub Pages to Deliver Stealer Malware<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Florence Nightingale<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/cyber-attack-attacking-macos-users\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Massive Cyber-Attack Attacking macOS Users via GitHub Pages to Deliver Stealer Malware A sophisticated cyber-attack campaign exploiting GitHub Pages to distribute the notorious Atomic stealer malware to macOS users.\u00a0 The threat actors behind this operation are leveraging Search Engine Optimization (SEO) techniques to position malicious repositories at the top of search results across major platforms, [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[701,129,63,258],"tags":[130],"class_list":["post-7105","post","type-post","status-publish","format-standard","hentry","category-cyber-attack","category-cyber-security","category-cyber-security-news","category-malware","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/7105"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=7105"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/7105\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=7105"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=7105"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=7105"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}