A newly disclosed macOS threat known as MacSync integrates credential theft, keychain harvesting, and a native remote access trojan into a single six-stage attack chain aimed at draining victims' browsers, accounts, and cryptocurrency wallets This article explores threat known macsync. . Security researchers from Huntress discovered the malware after investigating an intrusion where a user was redirected to run the malicious software by clicking on a sponsored ad while searching for "how to install Claude on a Mac."
The infection began when the victim searched Google for "Claude installation guide" and clicked on a poisoned AI chatbot conversation instead of the organic listing, leading them to a weaponized Claude.ai/share conversation.
A thin zsh loader inflates a second-stage script that fetches a server-side AppleScript stealer, tricking victims into granting Full Disk Access, validating stolen account passwords against Apple’s dscl authentication service, and harvesting Chromium browser Safe Storage keys directly from the keychain. That same stage installs a persistent, statically linked Mach-O RAT via a macOS LaunchAgent that masquerades as legitimate updaters such as Google Keystone or Adobe ARM, allowing it to blend into normal system activity while communicating over an encrypted WebSocket channel to a hardcoded IP-based command server. Cut SOC investigation blind spots and prevent threats from spreading with ANY.RUN.











