Mac users searching Google for a Claude install guide are getting something nastier: MacSync, a six-stage stealer and RAT chain that lives off a weaponized Claude share and a copy-paste curl command. It phishes passwords, rips browser and keychain data, abuses TCC, then rewrites crypto wallet apps to harvest seed phrases and hand full control to the attacker. Learn more in this blog post by Josh Kiriakoff – and join our upcoming Tradecraft Tuesday episode where we will discuss this attack further!
The six stages of MacSync, from the pasted curl one-liner to the trojanized wallet apps