New Infinity Stealer malware grabs macOS data via ClickFix lures

2026-03-28T19:23:27Zdad9f8d39ae2227a6d55f557b075e0e0bd13e6d68d682c420f3314e89bd3cb63
AWSCISACVE-2026-33017CorunaEuropean-CommissionGitHubLangflowNuitkaPyPIPythonTeamPCPWAVactive-exploitationcloud-breachcredential-theftdeveloper-targetingexploit-kitiOSinfo-stealermacOSmalwarephishingsanctions','data-breachsteganographysupply-chain

What happened

Multiple active campaigns and supply‑chain incidents were reported: Infinity Stealer (macOS info‑stealer) uses a Python/Nuitka executable and ClickFix lures to harvest data; a Telnyx PyPI package was backdoored (TeamPCP) to deliver credential‑stealing malware hidden in a WAV file; fake VS Code security alerts on GitHub are being used to trick developers into downloading malware. Separately, CISA warned of active exploitation of a critical Langflow vulnerability (CVE-2026-33017) that can hijack AI workflows, while the European Commission is investigating an Amazon cloud account breach. Other IO

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
dad9f8d39ae2227a6d55f557b075e0e0bd13e6d68d682c420f3314e89bd3cb63
Enrichment time
2026-03-28T19:23:27Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.