Scan to download
BTC $62,814.06 -0.44%
ETH $1,666.57 -0.90%
BNB $597.51 -0.73%
XRP $1.13 -0.30%
SOL $65.87 -0.81%
TRX $0.3251 -0.44%
DOGE $0.0851 -0.70%
ADA $0.1669 +2.12%
BCH $205.75 -6.97%
LINK $7.85 -0.78%
HYPE $62.25 +1.32%
AAVE $62.05 -1.56%
SUI $0.7453 -1.02%
XLM $0.1983 -1.88%
ZEC $447.21 +3.77%
BTC $62,814.06 -0.44%
ETH $1,666.57 -0.90%
BNB $597.51 -0.73%
XRP $1.13 -0.30%
SOL $65.87 -0.81%
TRX $0.3251 -0.44%
DOGE $0.0851 -0.70%
ADA $0.1669 +2.12%
BCH $205.75 -6.97%
LINK $7.85 -0.78%
HYPE $62.25 +1.32%
AAVE $62.05 -1.56%
SUI $0.7453 -1.02%
XLM $0.1983 -1.88%
ZEC $447.21 +3.77%

Malware Reaper steals cryptocurrency wallet data by hijacking the macOS Script Editor

2026-06-09 09:37:54
Collection

According to Cryptopolitan, a new type of macOS malware named Reaper is spreading through fake download pages of applications like WeChat and Miro, targeting the theft of cryptocurrency wallet data, browser passwords, and sensitive documents. This malware exploits the AppleScript URL to trigger the system's built-in script editor, hiding malicious code through ASCII art and spaces. After users click the run button, a fake Apple security update pop-up lures victims into entering their computer passwords.

Reaper targets desktop cryptocurrency applications such as Ledger Live, Trezor Suite, and Exodus, modifying the internal code of wallets to intercept future transactions and redirect funds. It also steals saved credentials from Chrome, Firefox, and Edge, extracting files like .docx, .pdf, and .wallet from the desktop and documents folder. Reaper also installs a backdoor disguised as a Google software update directory for persistent attacks. Security experts advise users to verify download links, avoid entering passwords in unexpected pop-ups, and immediately close the page if a website requests to open the script editor.

app_icon
ChainCatcher Building the Web3 world with innovations.