New Infinity Stealer malware grabs macOS data via ClickFix lures
2026-03-29T01:23:37Z•4d2c95b0a330b7772f3412a6e130786724309334955a687d2111b20b505ec74f
AI-securityAmazon AWSCISACVE-2026-33017GitHubLangflowNuitkaPyPIWAVcloud-compromisecredential-theftdeveloper-targetinginfo-stealermacOSmalwarephishingpythonsocial-engineeringsteganographysupply-chain
What happened
Multiple active security incidents and campaigns: a new Infinity Stealer targets macOS with a Nuitka-packaged Python info‑stealer using ClickFix lures; the Telnyx PyPI package was backdoored to deliver credential‑stealing malware hidden in a WAV file (supply‑chain compromise); GitHub Discussions are being abused with fake VS Code security alerts to spread malware to developers; CISA warns of active exploitation of a critical Langflow vulnerability (CVE-2026-33017) that can hijack AI workflows. Additional notable incidents include a breach of an Amazon cloud account affecting the European Commm
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 4d2c95b0a330b7772f3412a6e130786724309334955a687d2111b20b505ec74f
- Enrichment time
- 2026-03-29T01:23:37Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.