CYBERSECURITYTRACKER
TRACKING
Permanent story citation

MacSync Stealer: How a Google Search for Claude Led to a macOS Infostealer

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 4635

As cited

Copy frozen at (site build).

threat intel

MacSync Stealer: How a Google Search for Claude Led to a macOS Infostealer

Huntress SOC analysts reverse-engineered MacSync Stealer, a macOS infostealer distributed via counterfeit Claude Code download pages that users find through Google searches. The malware targets Apple system users seeking legitimate development tools and steals information from infected hosts.

Why it matters: macOS users are at risk when searching for popular development tools; practitioners should alert users to verify download sources and consider restricting unsigned or unverified application execution.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

MacSync Stealer: How a Google Search for Claude Led to a macOS Infostealer

Huntress SOC analysts reverse-engineered MacSync Stealer, a macOS infostealer distributed via counterfeit Claude Code download pages that users find through Google searches. The malware targets Apple system users seeking legitimate development tools and steals information from infected hosts.

Why it matters: macOS users are at risk when searching for popular development tools; practitioners should alert users to verify download sources and consider restricting unsigned or unverified application execution.

VendorsAppleGoogle
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary