Scam Radar

How can you recognize ClickLock Stealer: Mac users forced to hand over password via fake Cloudflare verification?

Published

Listen to the episode

TLDR

The ClickLock Stealer is a new macOS infostealer delivered through ClickFix style phishing pages that mimic Cloudflare human verification. Victims are tricked into pasting a malicious shell command into Terminal, which then steals browser...

How it works

The ClickLock Stealer is a new macOS infostealer delivered through ClickFix style phishing pages that mimic Cloudflare human verification. Victims are tricked into pasting a malicious shell command into Terminal, which then steals browser...

Red flags

  • A webpage asks you to open Terminal and paste a command as a "human verification" step A sudden macOS password dialog appears with your real username and an Apple icon Your Mac locks down to a single password prompt while Finder, Dock and browsers vanish

What to do

  1. 1Never copy paste or run commands from untrusted websites, emails or messages Verify any verification instructions via official documentation before acting Update macOS (Tahoe 26.4+ warns about ClickFix) and keep endpoint protection active

Source

FAQ

Is ClickLock Stealer: Mac users forced to hand over password via fake Cloudflare verification a real scam pattern?

Yes. Treat the message, call, or payment request as suspicious until you verify it through an official channel.

What are the first warning signs?

A webpage asks you to open Terminal and paste a command as a "human verification" step A sudden macOS password dialog appears with your real username and an Apple icon Your Mac locks down to a single password prompt while Finder, Dock and browsers vanish

What should I do first?

Never copy paste or run commands from untrusted websites, emails or messages Verify any verification instructions via official documentation before acting Update macOS (Tahoe 26.4+ warns about ClickFix) and keep endpoint protection active

Can LegalAudit check my case?

Yes. Start a free chat and paste the message, link, sender, or payment details for triage.