New Infinity Stealer malware grabs macOS data via ClickFix lures

2026-03-29T01:23:37Z4d2c95b0a330b7772f3412a6e130786724309334955a687d2111b20b505ec74f
AI-securityAmazon AWSCISACVE-2026-33017GitHubLangflowNuitkaPyPIWAVcloud-compromisecredential-theftdeveloper-targetinginfo-stealermacOSmalwarephishingpythonsocial-engineeringsteganographysupply-chain

What happened

Multiple active security incidents and campaigns: a new Infinity Stealer targets macOS with a Nuitka-packaged Python info‑stealer using ClickFix lures; the Telnyx PyPI package was backdoored to deliver credential‑stealing malware hidden in a WAV file (supply‑chain compromise); GitHub Discussions are being abused with fake VS Code security alerts to spread malware to developers; CISA warns of active exploitation of a critical Langflow vulnerability (CVE-2026-33017) that can hijack AI workflows. Additional notable incidents include a breach of an Amazon cloud account affecting the European Commm

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
4d2c95b0a330b7772f3412a6e130786724309334955a687d2111b20b505ec74f
Enrichment time
2026-03-29T01:23:37Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · New Infinity Stealer malware grabs macOS data via ClickFix lures · Baitaphish