The Huntress research team has discovered a new macOS malware named MacSync. Victims searching Google for “how to install Claude on Mac” click on a fake advertisement.
Key points to know:
• The phishing page was hosted on the legitimate claude.ai/share domain, so there were no warning signs of a fake URL.
• Users are instructed to copy a curl command into Terminal — this is when the malware initiates infection.
• It steals passwords stored in browsers, Keychain, SSH keys, and Telegram sessions.
• It modifies Ledger Live and Trezor Suite to prompt for a fake Seed Phrase (targeting 60 wallet extensions).
[Insight: Do not copy-paste Terminal commands from any website, even if it appears official. Seed Phrases should only be typed directly into the hardware wallet itself.]
Kun Long
Author at The Sharing KH