• News/
  • https://www.bleepingcomputer.com/news/security/lastpass-fake-password-managers-infect-mac-users-with-malware/

LastPass: Fake password managers infect Mac users with malware

BleepingComputer
·
Bill Toulas
·
Published Sep 22, 2025
·
Updated

LastPass is warning users of a campaign that targets macOS users with malicious software impersonating popular products delivered through fraudulent GitHub repositories. The fake apps deliver the Atomic (AMOS) info-stealing malware in ClickFix attacks, and are promoted through search engine optimization (SEO) tactics on Google and Bing. AMOS is a malware-as-a-service operation available for $1,000/month that typically targets data on infected machines. Recently, the developers of the malware added a backdoor component, giving attackers persistent, stealthy access to compromised systems. LastPass says that apart from its product, the campaign impersonates more than 100 software solutions, like 1Password, Dropbox, Confluence, Robinhood, Fidelity, Notion, Gemini, Audacity, Adobe After Effects, Thunderbird, and SentinelOne. The attackers created a large number of deceptive GitHub repositories from multiple accounts to evade takedown and optimize them to rank high in search results. These repositories feature a “download button” that directs visitors to a secondary site, where they are prompted to paste a command into the Terminal to perform the installation. This is a typical ‘ClickFix’ attack that takes advantage of the victim not understanding what the command does on their system. The command performs a curl request to a base64-encoded URL and downloads an AMOS payload (install.sh) to the /tmp directory. ClickFix attacks targeting Apple computers aren’t rare. BleepingComputer...

Read full article

Affected Software

12 affected components
LastPass LastPass
1Password 1Password
Dropbox dropbox
Confluence Confluence
Robinhood Robinhood
Fidelity Fidelity
Notion Notion
Gemini Gemini
Audacity Audacity
Adobe After Effects
Thunderbird Thunderbird
SentinelOne SentinelOne
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the primary security issue discussed in the article?

The article highlights a campaign targeting macOS users with fake password managers that deliver malware.

2

What type of malware is being distributed through these fake password managers?

The fake apps are spreading the Atomic (AMOS) info-stealing malware.

3

Which operating system are the affected users primarily using?

The affected users are primarily using macOS.

4

What are examples of legitimate products being impersonated by these fake apps?

The fake password managers impersonate popular products like LastPass, 1Password, and Dropbox.

5

What is a key recommendation for users to avoid falling victim to this malware campaign?

Users are advised to download software only from official websites to avoid fake applications.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203