macOS Stealer Spoofs Apple, Google, and Microsoft in a Single Attack Chain

Reported 18 May 2026 by otx · Severity: medium

A new variant of SHub Stealer dubbed 'Reaper' targets macOS users through fake WeChat and Miro installers, employing sophisticated multi-stage delivery chains that spoof Apple, Google, and Microsoft services. The malware leverages the applescript:// URL scheme to bypass Terminal-