A new macOS information stealer called AmnesiaStealer is using ClickFix-style attacks to move beyond basic credential theft into live browser-session control, according to BleepingComputer, citing research from Apple device management and security company Jamf. The reported technique matters because it targets the session layer, not just stored passwords. BleepingComputer says AmnesiaStealer can copy a victim’s Chromium profile, including its authentication state, and load that profile into a hidden headless browser running on the infected Mac. That setup can preserve identifiers associated with the victim’s browser, host and network while the operator interacts with already-authenticated web sessions. According to the report, AmnesiaStealer can collect data from 16 Chromium-based browsers, along with passwords, cryptocurrency wallets, Apple Notes, documents and keychain data. BleepingComputer also says the malware captures the victim’s macOS password and uses it to collect keychain data, browser profiles, Apple Notes, Telegram sessions, documents, system information and cryptocurrency wallet data. The distribution path described by Jamf is a ClickFix campaign built around a fake GitHub download page. BleepingComputer reports that the page drops a password-protected ZIP archive, while the ClickFix command executes a shell-script loader that downloads and launches the archive containing the AmnesiaStealer Mach-O payload. Jamf also found that the campaign used the same template previously associated with distribution of the Atomic and MacSync infostealers, according to the report. The most notable component is a streaming feature Jamf identified as stream_module, retrieved through a remote_stream command. BleepingComputer says this component lets the attacker operate authenticated sessions created from a headless browser instance. Jamf found that the module can duplicate user profiles in seven Chromium-based browsers: Google Chrome, Microsoft Edge, Vivaldi, Arc, Opera, Brave and Chromium. The compatibility comes from shared browser plumbing, according to the report. Those browsers use the same Chrome DevTools Protocol, launch flags and cookie-encryption approach, allowing the malware to start the legitimate browser executable in headless mode, weaken defenses with command-line switches, duplicate the victim’s profile and set where the profile data is stored. BleepingComputer says the malware then establishes a WebSocket channel to the operator’s relay and sends a JSON registration message with the browser name and build. The attacker can issue navigation and mouse-click commands over that connection, while the malware returns status and tab information as JSON and sends screencast frames as binary WebSocket messages. A second WebSocket channel connects to the local headless Chromium instance through the browser’s webSocketDebuggerUrl, giving access to the Chrome DevTools Protocol. That allows the operator to navigate sites with mouse and keyboard input, export or import cookies, and operate online portals using the victim’s existing authenticated sessions, according to BleepingComputer’s summary of Jamf’s findings. This is still a single-reported cluster, but the technical detail is concrete. For security teams managing macOS fleets, the report points to a threat chain that starts with user-executed ClickFix commands and ends with remote use of live browser sessions rather than only exfiltrated credential files. Who benefits: Attackers benefit from session access that can be driven through a victim’s own browser context. Defenders benefit from the detailed indicators in the reported chain: ClickFix lures, fake GitHub pages, password-protected ZIP delivery, shell-script loading and headless Chromium activity. Who's exposed: macOS users who run ClickFix commands from fake download pages are the directly exposed group described in the report. Organizations with managed Apple fleets and heavy use of Chromium-based browsers should treat the browser-session angle as the core risk in this analysis.