AI INFRASTRUCTURE

New Mac Malware Reaper Exposes Crypto Data via Script Editor

The Reaper malware is stealing crypto wallet data from Mac users by exploiting Script Editor, bypassing recent security updates from Apple.

New Mac Malware Reaper Exposes Crypto Data via Script Editor
CoinSynaptic Desk
AI INFRASTRUCTURE · Correspondent
· PUBLISHED JUN 9, 2026 · 2 MIN READ

A newly discovered malware strain, dubbed Reaper, is threatening macOS users by stealing cryptocurrency wallet information and saved browser passwords. This malware primarily spreads through counterfeit download pages for popular applications like WeChat and Miro, tricking users into installing the malicious software.

Reaper stands out for its advanced infiltration techniques, which exploit vulnerabilities that Apple had previously patched in recent updates. The malware bypasses these fixes by utilizing Script Editor, a built-in tool present on all Mac computers. Unlike traditional methods that depended on Terminal commands, Reaper activates its payload through an AppleScript applescript:// URL initiated by fake download sites.

The Mechanics of the Attack

Once installed, Reaper executes hidden commands obscured with ASCII art and whitespace, making them nearly invisible to the average user. When a victim clicks the play button in Script Editor, they unintentionally run the malicious code. This sophisticated approach takes advantage of users’ general lack of awareness regarding malware risks, especially on Mac systems, where many do not associate their devices with traditional viruses.

The initial phase of the attack relies on social engineering tactics. Cybercriminals create typosquatted domains that closely mimic legitimate Microsoft sites, such as mlcrosoft[.]co[.]com, to establish credibility. After reaching these deceptive domains, victims encounter a fraudulent Apple security update dialog, misleading them into entering their computer passwords.

Targeting the Unwary

Once the script is activated, Reaper checks the system’s keyboard layout. If the layout is set to Russian, the malware halts its operations, likely to avoid detection or limit its spread in certain regions. However, if the keyboard is configured to other languages, the malware activates a data-theft module modeled after the notorious Atomic macOS Stealer (AMOS).

See also  Temporal's Workflow Platform Enhances AI Agent Orchestration

The implications of Reaper are significant for crypto holders who use wallet applications like Ledger Live, Trezor Suite, and Exodus. As the cyber threat landscape continues to evolve, the emergence of such sophisticated malware highlights the need for vigilance and proactive security measures among users.

A Call for Enhanced Security

Given these developments, the necessity for stronger security protocols is evident. Users should be cautious about where they download applications and stay informed about potential phishing schemes. As cybercriminals become more skilled at exploiting user trust and technological vulnerabilities, both individuals and companies like Apple and Microsoft must prioritize cybersecurity to protect sensitive information from emerging threats like Reaper.

As the crypto market expands, so does the allure for hackers looking to exploit weaknesses in user security. The Reaper malware serves as a stark reminder of the evolving nature of cybersecurity threats, urging both users and developers to adapt and bolster their defenses accordingly.

Quick answers

What is the Reaper malware?

Reaper is a new type of malware targeting macOS users, stealing cryptocurrency wallet data and saved passwords.

How does Reaper infect Mac computers?

Reaper spreads through fake download pages for apps and uses Script Editor to execute hidden commands.

What precautions can users take to avoid Reaper?

Users should be cautious of download sources, avoid entering passwords in suspicious prompts, and keep their systems updated.

CoinSynaptic Desk

AI Infrastructure · 2,404 stories

CoinSynaptic Desk covers the intersection of artificial intelligence and decentralized networks — frontier AI infrastructure, crypto-native AI agents, Bittensor subnets, DePIN economies, and tokenized compute.

THE DAILY SIGNAL

The stories that move AI & crypto markets — before the market reacts.

Free. 7am ET. Five stories. 62,400 readers.