
Mac users are encountering fake CAPTCHA checks, download prompts and troubleshooting pages that tell them to open Terminal and paste a command, just like on a Windows PC. That “verification,” however, can install an information stealer instead.
Just a few days ago, Microsoft tracked campaigns that use this ClickFix tactic to deliver MacSync and Atomic Stealer (AMOS), but it has been happening for a while. The message is simple: while macOS security features help, they won’t protect users if they run the attacker’s command themselves.
ClickFix is a type of scam that turns a victim into the person who launches the malware. Instead of tricking the user into downloading a suspicious app, a website will display a fake error, a CAPTCHA prompt, or an installation step. It then instructs the victim to copy a command, open Terminal, paste it and press Enter.
No. ClickFix attacks target Mac users with fake CAPTCHAs, download pages and troubleshooting guides that tell them to paste a command into Terminal. This simple action can download the infostealer malware, which may steal browser data, Keychain entries, iCloud-related data and cryptocurrency wallet information.
A legitimate CAPTCHA never asks you to open Terminal or paste a command.
Apple’s security layers, including Gatekeeper, code-signing checks and notarization, offer users protection against many malicious applications.
When a user launches a downloaded app through Finder, macOS can apply its normal application-trust checks. When that same user runs a command in Terminal, the command can retrieve scripts or payloads remotely.
That does not mean macOS is insecure. It means the attacker has shifted from defeating a technical barrier to defeating the user. Dedicated security software and platform defenses can still detect parts of the chain, but no product can make “paste this unknown command into Terminal” a safe decision.
The malware behind Mac ClickFix attacks usually aims to steal information, not display ads or slow down a computer. Attackers may use stolen browser sessions, saved passwords and authentication data to take over accounts after the initial infection. That makes a successful ClickFix attack potentially wider than a single compromised Mac.
For example, Bitdefender researchers documented the same deception in a March 2026 campaign that abused Google Ads to impersonate Claude Code. A sponsored result led people to a fake documentation page hosted on a Squarespace subdomain; Mac visitors received an obfuscated command that decoded content and fetched a Mach-O backdoor.
Follow this rule: a website must never require Terminal to prove that you are human. Close the page if it asks you to:
For families and small businesses, explain the rule in plain language: don’t paste website text into Terminal unless you understand exactly what it does and you trust the source. That one habit breaks the ClickFix chain before it starts.
Disconnect from Wi-Fi or Ethernet first. Then, from a known-clean device, change the passwords for your email, Apple Account, password manager, financial accounts and any account that was signed in on the Mac. Revoke any active sessions for online services.
Answer: A CAPTCHA page alone does not infect the Mac. The danger starts when the page tricks you into copying and running a malicious Terminal command, which can download malware.
Answer: macOS provides important protection, but ClickFix tries to bypass normal app-download checks by persuading you to execute a command yourself. Don’t run commands that a website gives you unless you fully understand and trust them.
Answer: Any “verification,” update or download page that tells you to open Terminal and paste text is a major red flag. Legitimate CAPTCHAs do not require that step.
Answer: Disconnect from the internet, change important passwords from another clean device, revoke active sessions and have the Mac scanned or reviewed. If cryptocurrency wallets were present, treat wallet credentials as exposed.
tags
Silviu is a seasoned writer who followed the technology world for almost two decades, covering topics ranging from software to hardware and everything in between.
View all posts