PureLogs infostealer is stealing credentials worldwide

2026-05-19T14:51:44Ze050a73c5f992bb47532a43f0143aefe85c9870c252e7fc4c47430ae45bb8a35
AI-phishingFortinetJavaScriptPureLogsReaperSHubSentinelOneTXZ archivecredential theftinfostealermacOSmalwarephishingprocess environment variablessocial engineeringsocial media scrapingsteganography

What happened

Fortinet researchers uncovered a worldwide phishing campaign delivering the PureLogs infostealer by hiding encrypted payloads inside images (steganography) embedded in a TXZ archive attached to invoice-themed emails. The attack unpacks JavaScript that stores malicious commands in process environment variables and ultimately harvests credentials (browser data, password managers, crypto wallets). Related reporting highlights additional credential-theft trends: a new SHub macOS infostealer (“Reaper”) that impersonates Apple/Microsoft/Google to lure victims, and research showing public Instagram帖子

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
helpnetsecurity
Record identifier
e050a73c5f992bb47532a43f0143aefe85c9870c252e7fc4c47430ae45bb8a35
Enrichment time
2026-05-19T14:51:44Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · PureLogs infostealer is stealing credentials worldwide · Baitaphish