SHub Reaper | macOS Stealer Spoofs Apple, Google, and Microsoft in a Single Attack Chain
2026-05-18T20:51:47Z•2ee82207a496c18aa8bfa25c37b34fe239ee9a6977a4610c4e5893b8b7f8e61e
AI securityApple Terminal bypassCI/CD subversionEDRSentinelOnebackdoorcloud secretscredential theftmacOSmalwarepersistencered teamingsoftware supply chainspoofingstealersupply chainthreat researchwatering‑hole
What happened
This SentinelOne RSS feed (May 2026) highlights multiple recent threat and defense write-ups—most notably an in-depth analysis of “SHub Reaper,” a macOS stealer that spoofs Apple/Google/Microsoft, bypasses Apple Terminal mitigations, exfiltrates credentials and documents, and installs a persistent backdoor for continued access. Other posts cover CI/CD pipeline subversion, supply‑chain/watering‑hole attacks (CPU‑Z, LiteLLM/Axios), cloud secrets and AI risk, red‑teaming AI systems, and the role of AI-native EDR and machine‑speed automation in detection and mitigation. No CVE identifiers are in-s
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sentinelone_blog
- Record identifier
- 2ee82207a496c18aa8bfa25c37b34fe239ee9a6977a4610c4e5893b8b7f8e61e
- Enrichment time
- 2026-05-18T20:51:47Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.