New Infinity Stealer malware grabs macOS data via ClickFix lures
2026-03-29T13:23:29Z•238d23562ca570e038d7a42cda13d551aedb3c7f169cdb50a422d8ffd1289050
AI-securityAWSCISACVE-2026-33017European-CommissionGitHubLangflowNuitkaPyPIPythonWAVbackdoorcloud-breachdata-breachdeveloper-targetingiOS-exploitinfostealermacOSmalwarephishingsocial-engineeringsteganographysupply-chainvulnerabilityzero-click (iMessage)
What happened
A cluster of active security incidents and supply-chain attacks was reported: a new macOS info‑stealer dubbed Infinity Stealer (Python payload compiled with Nuitka) is being distributed via ClickFix lures; the Telnyx PyPI package was backdoored (attributed to TeamPCP) to deliver credential‑stealing malware hidden inside a WAV file; and a large campaign is spreading malware to developers via fake VS Code security alerts posted in GitHub Discussions. CISA warned that a critical Langflow flaw (CVE-2026-33017) is being actively exploited to hijack AI workflows. Separately, the European Commission,
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 238d23562ca570e038d7a42cda13d551aedb3c7f169cdb50a422d8ffd1289050
- Enrichment time
- 2026-03-29T13:23:29Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.