HomeIntelligenceBrief
BREACH BRIEF🟠 High ThreatIntel

Reaper macOS Infostealer Exploits Script Editor to Steal Cryptocurrency and Passwords

A new SHub Stealer variant, Reaper, abuses macOS Script Editor to bypass security controls and exfiltrate crypto wallet files and saved passwords, posing a high‑risk threat to enterprises with macOS endpoints.

LiveThreat™ Intelligence · 📅 June 06, 2026· 📰 hackread.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
3 sector(s)
Actions
3 recommended
📰
Source
hackread.com

Reaper macOS Infostealer Leverages Script Editor to Harvest Crypto Wallets and Passwords

What Happened — Threat actors have released a new variant of the SHub Stealer family, dubbed Reaper, that abuses the native macOS Script Editor to bypass built‑in security controls and exfiltrate cryptocurrency wallet files and saved passwords. The malware runs user‑level scripts that silently capture private keys and credential stores.

Why It Matters for TPRM

  • macOS endpoints are common in many enterprise environments; a breach can lead to direct financial loss and credential reuse.
  • The technique circumvents traditional endpoint protection that relies on binary whitelisting.
  • Third‑party vendors providing macOS device management may be unaware of this novel attack vector.

Who Is Affected — Enterprises with macOS workstations, managed service providers supporting macOS, and end‑users handling crypto assets.

Recommended Actions

  • Review macOS endpoint security controls and ensure script execution monitoring is enabled.
  • Enforce strict application allow‑lists that include Script Editor usage policies.
  • Verify that cryptocurrency wallets are stored in encrypted, hardware‑isolated solutions.

Technical Notes — The malware exploits the Script Editor’s ability to run AppleScript/JavaScript for Automation (JXA) without triggering Gatekeeper. No specific CVE is cited; the abuse is a novel malicious script technique. Data exfiltrated includes wallet files (e.g., .keychain, .dat) and password stores from browsers and password managers. Source: HackRead

📰 Original Source
https://hackread.com/reaper-macos-infostealer-script-editor-crypto-passwords/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Monitor Your Vendor Risk with LiveThreat™

Get automated breach alerts, security scorecards, and intelligence briefs when your vendors are compromised.