Fake Homebrew Sites Use ClickFix to Deliver Cuckoo Stealer on macOS

Summary
Researchers analyzed a macOS ClickFix campaign using typosquatted Homebrew pages to steal credentials and deliver Cuckoo Stealer, a persistent RAT that can collect sensitive data and execute commands.
Key points
- Fake Homebrew pages silently copy a malicious curl command to users’ clipboards, leading them to download and run a script in Terminal.
- The modified installer repeatedly prompts for a password and validates it with macOS Directory Services before downloading the second-stage payload.
- Cuckoo Stealer installs a LaunchAgent, removes the downloaded file’s quarantine attribute, and uses encrypted HTTPS command-and-control to receive commands.
- The malware can run shell commands, capture screenshots, browse and exfiltrate files, and remove its persistence and installation directory.
- Targets include browser credentials and sessions, macOS Keychain data, Apple Notes, messaging sessions, VPN and FTP configurations, documents, and data from more than 20 cryptocurrency wallets.
- Infrastructure hunting linked multiple Homebrew-impersonating domains to shared hosting and identified dozens of similar macOS-targeting pages.
Article Details
- Attack Vectors
- High-fidelity Homebrew impersonation pages on typosquatted domains persuade users to copy a malicious installation command into Terminal.
- The installation command substitutes an attacker-controlled script host for the legitimate Homebrew distribution host and downloads and executes a modified installer through curl and bash.
- The modified installer repeatedly requests a password and validates it with dscl authonly before downloading the second-stage binary and passing the Base64-encoded password as an argument.
- Defensive Notes
- The researchers hunted for pages containing curl commands, -fsSL flags, /install.sh references, and copy-to-clipboard functionality. These behavioral matches require investigation rather than automatically establishing maliciousness.
- Infrastructure pivots used domain registration records, shared hosting, certificate history, and phishing detections to identify related delivery infrastructure.
- Reported persistence artifacts include ~/Library/LaunchAgents/com.homebrew.brewupdater.plist, the label com.homebrew.brewupdater, and ~/.local-{session_id}/BrewUpdater.
- The malware removes quarantine attributes, encrypts sensitive strings, and supports deleting its LaunchAgent and installation directory, complicating detection and forensic investigation.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| DOMAIN | braw[.]sh | Homebrew typosquat variant listed as malicious network infrastructure. |
| DOMAIN | brew[.]lat | Homebrew typosquat variant listed as malicious network infrastructure. |
| DOMAIN | brewmacos[.]com | Domain identified by the researchers among additional macOS ClickFix pages. |
| DOMAIN | brewsh[.]cx | Homebrew typosquat hosted on the shared malicious infrastructure. |
| DOMAIN | brewshh[.]org | Homebrew impersonation domain identified through the shared-infrastructure pivot. |
| DOMAIN | brrewsh[.]org | Homebrew impersonation domain identified through the shared-infrastructure pivot. |
| DOMAIN | homabrews[.]org | Homebrew impersonation domain used for payload delivery and identified in the IOC table as the primary C2 domain. |
| HOSTNAME | bashbuddy-landing[.]pages[.]dev | Cloudflare Pages hostname identified by the researchers as broader macOS ClickFix activity. |
| HOSTNAME | brew[.]pages[.]dev | Specific hosted Homebrew typosquat listed as malicious network infrastructure. |
| HOSTNAME | raw[.]brewsh[.]cx | Homebrew typosquat variant listed as malicious network infrastructure. |
| HOSTNAME | raw[.]homabrews[.]org | Attacker-controlled host serving the modified Homebrew installation script. |
| HOSTNAME | www[.]nitrogen[.]lol | Hostname identified by the researchers among additional macOS ClickFix pages. |
| IPV4 | 5[.]255[.]123[.]244 | Shared malicious infrastructure hosting Homebrew typosquats; identified as shared C2 infrastructure. |
| SHA256 | 545dd5cba264bf242bc837330ca34247e202f7ac25f03eec63bf5842357519f1 | Cuckoo Stealer hash listed in the file indicators. |
| SHA256 | f985cd667c77e7d99c1ac2ea9cb0861ded15e1c2d44e480cbd178ca8b2caae42 | Loader hash listed in the file indicators. |
| URL | hxxps[:]//homabrews[.]org/brewinstaller | Download URL for the second-stage binary named brew_agent. |
| URL | hxxps[:]//raw[.]homabrews[.]org/Homebrew/install/HEAD/install[.]sh | Malicious installer URL embedded in the fake Homebrew installation command. |
MITRE ATT&CK
T1005 · Data from Local SystemThe malware collects local documents, Desktop files, Apple Notes, messaging data, and cryptocurrency wallet files.T1027 · Obfuscated Files or InformationSensitive strings, including paths, commands, and network endpoints, are concealed with an index-based XOR scheme.T1036.005 · Match Legitimate Resource Name or LocationThe persistence binary and LaunchAgent use BrewUpdater and com.homebrew.brewupdater names to resemble Homebrew components.T1041 · Exfiltration Over C2 ChannelScreenshots and stolen data are transmitted to the C2 server through the malware's communication protocol.T1056 · Input CaptureThe modified installer captures passwords through repeated prompts and validates them using dscl authonly.T1059.002 · AppleScriptAppleScript performs file enumeration and copying and temporarily mutes system audio during exfiltration.T1059.004 · Unix ShellThe delivery chain uses bash and curl; the RAT also executes arbitrary shell commands and uses bash for delayed self-deletion.T1070.004 · File DeletionA C2 uninstall command removes the LaunchAgent and starts a delayed bash process to delete the installation directory.T1071.001 · Web ProtocolsThe malware polls its C2 server over HTTPS using libcurl.T1074.001 · Local Data StagingKeychain files are copied to a temporary location, screenshots are saved temporarily, and wallet files are staged before exfiltration.T1083 · File and Directory DiscoveryThe malware recursively traverses wallet directories and supports remote filesystem browsing and directory listing.T1105 · Ingress Tool TransferThe first-stage script downloads brew_agent from the attacker-controlled brewinstaller endpoint.T1113 · Screen CaptureThe malware executes screencapture -x -t jpg to capture screenshots silently before exfiltration.T1119 · Automated CollectionCollection routines systematically traverse application and wallet storage and collect files matching targeted patterns.T1204.002 · Malicious FileVictims manually run a copied Terminal command that downloads and executes the malicious installer.T1518 · Software DiscoveryThe article reports browser and wallet application detection as part of the collection workflow.T1528 · Steal Application Access TokenThe malware collects Discord authentication tokens and Telegram session keys that can enable account or session takeover.T1529 · System Shutdown/RebootA RAT command triggers a system restart using reboot -l.T1539 · Steal Web Session CookieThe malware collects browser cookies and session data.T1543.001 · Launch AgentCuckoo Stealer creates com.homebrew.brewupdater.plist under the user's LaunchAgents directory for persistence.T1552.001 · Credentials In FilesThe malware steals FileZilla credential files and OpenVPN profiles that may contain credentials or private keys.T1552.004 · Private KeysSSH private keys are explicitly included among the malware's theft targets.T1553.001 · Gatekeeper BypassThe malware uses xattr to remove the macOS quarantine attribute and avoid Gatekeeper warnings.T1555.001 · KeychainThe malware copies ~/Library/Keychains to steal stored credentials and other Keychain data.T1555.003 · Credentials from Web BrowsersBrowser harvesting routines extract saved login credentials from browser storage, including Chromium Login Data databases.T1564.001 · Hidden Files and DirectoriesThe persistent binary is placed in the hidden directory ~/.local-{session_id}/.T1573.001 · Symmetric CryptographyC2 beacon data is XOR-encrypted with an MD5-derived key based on the ECDH shared secret.T1573.002 · Asymmetric CryptographyAn ephemeral X25519 keypair and the server's embedded public key derive the shared secret for C2 encryption.T1614.001 · System Language DiscoveryThe malware checks LANG prefixes against hy_AM, be_BY, kk_KZ, ru_RU, and uk_UA and avoids full compromise for matching locales.
People
Malware
Vendors
CloudflaremacOS users beyond just Homebrew impersonation. Notable domains include bashbuddy-landing.pages[.]dev (Cloudflare Pages abuse), brewmacos[.]com, and www.nitrogen[.]lol. This demonstrates the broader trend of ClickFixNamecheapplatform revealed concerning indicators. The domain was registered on January 13, 2026, through NameCheap, Inc. Within 24 hours of registration, our phishing detection systems had already flagged the domain threeThe Infrastructure Group B.V.resolves to IP address 5.255.123[.]244, hosted in the Netherlands under AS60404 (The Infrastructure Group B.V.). This hosting provider has previously been observed hosting malicious infrastructure, a
Products
Apple Noteshigh-value data at scale: It collects browser credentials, session tokens, macOS Keychain data, Apple Notes, messaging sessions, VPN and FTP configurations, and over 20 cryptocurrency wallet applications.Binance Wallethmeobnfnfcmdkdcmlblgagmfpfboieaf (Binance Wallet)ChromiumThe malware targets all major browsers on macOS with comprehensive credential harvesting capabilities. Chromium-based browsers receive the most extensive coverage, with dedicated routines for extracting cookies, loginCoinbase Wallethnfanknocfeofbddgcijnmhnfnkdnaad (Coinbase Wallet)Discordtargets multiple messaging applications to steal authentication tokens and conversation data. For Discord, it extracts the Local Storage directory from ~/Library/Application Support/discord/Local Storage, whichFileZillaFileZilla FTP credentials are harvested from ~/.config/filezilla/, targeting both recentservers.xml and sitemanager.xml files which contain saved FTP server credentials in plaintext or weakly obfuscated format. OpenVPNHomebrewIn this case, the lure was Homebrew. We started with a single typosquatted domain and pivoted outward using Hunt.io. What looked like one fake install page turned out to be a coordinated infrastructure clustermacOSto be a coordinated infrastructure cluster delivering a credential-harvesting loader and a second-stage macOS infostealer we've designated Cuckoo Stealer.macOS KeychainThe malware targets high-value data at scale: It collects browser credentials, session tokens, macOS Keychain data, Apple Notes, messaging sessions, VPN and FTP configurations, and over 20 cryptocurrency walletMozilla FirefoxCredential Access T1555.003 Password Stores: Web Browsers Chromium/Firefox credentials extractedOpenVPNfiles which contain saved FTP server credentials in plaintext or weakly obfuscated format. OpenVPN configuration profiles are stolen from ~/Library/Application Support/OpenVPN Connect/profiles, which mayPhantom Walletaiifbnbfobpmeekipheeijimdpnlpgpp (Phantom Wallet)Rabby Walletbifidjkcdpgfnlbcjpdkdcnbiooooblg (Rabby Wallet)SteamSteam session data is harvested from ~/Library/Application Support/Steam/config/, specifically targeting loginusers.vdf (which contains account information and login tokens) and config.vdf (which contains configurationTelegramStorage, which contains authentication tokens that can be used for account takeover. For Telegram, it targets the tdata directory from both the standard installation path at ~/Library/Application
Tools
Hunt.iothis case, the lure was Homebrew. We started with a single typosquatted domain and pivoted outward using Hunt.io. What looked like one fake install page turned out to be a coordinated infrastructure cluster deliveringHuntSQLcentered on translating observable behaviors into structured, repeatable queries that can be run against HuntSQL's comprehensive dataset. The query focuses on four key indicators: the presence of curl commands, -fsSL