A website asking you to run a cleanup script can turn a routine maintenance task into a malware installation. On April 8, 2026, Jamf Threat Labs documented a ClickFix campaign that used a fake Apple storage-cleanup page to deliver Atomic Stealer through macOS Script Editor. The attack still required the user to approve prompts and run the script.
How the fake cleanup page reaches Script Editor
ClickFix uses a supposed problem or maintenance task to persuade someone to execute instructions supplied by an attacker. Jamf documented this sequence:
- The fake Apple page offers to reclaim disk space and presents an Execute button.
- The button invokes the
applescript://URL scheme. The browser asks permission to open Script Editor. - Script Editor presents a prepared script. Jamf also observed a warning about creating the script document on macOS 26.4.
- When the user runs it, the script downloads further code, eventually retrieving and executing an Atomic Stealer binary.
Jamf describes macOS 26.4 Terminal paste checks as context for this alternative route. Its screenshots show that Script Editor behavior varies by macOS version. The report does not establish how every browser and OS combination behaves.
Why an Apple application can carry unsafe instructions
Script Editor is an automation tool. Its presence tells you which application is handling the script; it does not establish who wrote the instructions or whether you should trust them. A browser permission prompt similarly asks whether to open an application. Treating either step as an endorsement of the website gives the attacker an opportunity to continue.
A useful check is whether you independently intended to perform this task and obtained the instructions from a source you trust. A page can copy a familiar logo, present polished instructions and claim that a repair succeeded. Those details do not verify what the script actually did. If ordinary browsing unexpectedly leads to a scripting application, stop and check the task through the vendor's own support site.
A separate campaign using a fake update shows the same trust problem
In research published April 16, 2026, Microsoft described a Sapphire Sleet intrusion using a supposed Zoom SDK update. A downloaded AppleScript opened in Script Editor, with harmless comments and thousands of blank lines concealing the malicious logic. Later stages presented a fake update password prompt and collected sensitive data. This was a separate intrusion from Jamf's cleanup-page campaign; the shared lesson is that familiar software and update language can lend credibility to instructions supplied by an attacker.
Reading the first few visible lines of an unfamiliar script offers little assurance about the rest of it. For a work device, ask your IT team to verify an unexpected update request through an established channel. For a personal Mac, open the installed application's update controls or navigate independently to the vendor's site.
What to do before running a script
- Cancel an unexpected request to open Script Editor. Close a prepared script without running or saving it, and leave the page that supplied it.
- Verify repairs and updates independently. Use macOS Settings, the application's own updater, or a support page you reached yourself. A recruiter, advertisement or unsolicited message should not decide which code runs on your Mac.
- Keep macOS and browsers updated. Leave security warnings enabled and investigate the reason for a warning before proceeding.
- Protect accounts as well as the device. Use unique passwords and multifactor authentication. Keep recovery information available somewhere you can access without the affected Mac.
If you already ran the script
Stop entering passwords into any follow-up dialogs. Disconnect the Mac from networks and contact your IT or security team if it is managed. Record the page address, approximate time and actions you took without reopening the script. That context helps an investigator distinguish a blocked attempt from code that actually ran.
Use a separate trusted device to secure potentially affected accounts, starting with email and other accounts used for recovery. Change exposed passwords and use the service's controls to revoke active sessions. Microsoft describes theft of browser cookies and Telegram session data in the Sapphire Sleet intrusion, so password changes alone may leave other access to address.
Have the Mac assessed before signing back into sensitive services. Closing Script Editor or deleting the original download does not establish that later components are gone. Keep backups for recovery, while treating any suspected exposure of accounts or files as a separate issue.
PhantomSecure development status
PhantomProtect is our first planned release and remains in development. We’re testing how local file checks, activity analysis and threat information work together. Results from those tests will establish which attacks a released build can detect or block.
Sources
- Jamf Threat Labs, April 8, 2026: ClickFix technique uses Script Editor instead of Terminal on macOS.
- Microsoft Security Blog, originally published April 16, 2026: Dissecting Sapphire Sleet's macOS intrusion from lure to compromise. This article discusses the Zoom-themed intrusion; Microsoft's source now also includes a June 2026 Teams-themed update.