Newly Discovered Reaper macOS Malware Steals Crypto Wallet Data via Script Editor Hijacking

According to Cryptopolitan, a new macOS malware called Reaper is spreading through fake download pages of apps including WeChat and Miro, targeting cryptocurrency wallet data, browser passwords, and sensitive documents. The malware exploits AppleScript URLs to trigger the system's built-in script editor, hiding malicious code using ASCII art and spaces. Upon execution, a spoofed Apple security update popup prompts victims to enter their computer password. Reaper specifically targets Ledger Live, Trezor Suite, and Exodus desktop applications, modifying wallet code to intercept future transactions and redirect funds. It also steals saved credentials from Chrome, Firefox, and Edge browsers, and extracts files including .docx, .pdf, and .wallet from desktop and document folders.
Disclaimer: The information on this page may come from third-party sources and is for reference only. It does not represent the views or opinions of Gate and does not constitute any financial, investment, or legal advice. Virtual asset trading involves high risk. Please do not rely solely on the information on this page when making decisions. For details, see the Disclaimer.
Comment
0/400
No comments