A dangerous new threat called ClickLock is targeting macOS users by tricking them into running malicious Terminal commands. Discovered by security researchers, this malware uses fake verification pages to steal passwords, browser data, and cryptocurrency wallet files. Since May 2026, the campaign has compromised at least 100 systems across 33 countries, locking users out of their applications until they provide their login credentials.
How does ClickLock malware work?
ClickLock malware operates by displaying a fake "verify you are human" page that instructs users to copy and paste a command into the Terminal app. Once executed, the script downloads malicious components in the background. It then displays a fraudulent macOS password window, repeatedly closing essential applications like Finder and web browsers until the user enters their system login password, which the malware then captures and transmits to attackers.
How can you protect your Mac from this threat?
To protect your system, never copy and paste commands from unknown websites into your Terminal, especially if prompted by a "verification" page. If you encounter a suspicious password prompt that repeatedly closes your apps, force quit the process immediately. Security experts recommend staying vigilant against phishing attempts and ensuring your macOS software is up to date to mitigate risks from similar evolving cyber threats.