Campaign record
SHub and MacSync via GitHub lures
Fake vendor GitHub repos funnel macOS users through ClickFix into MacSync and SHub
- Status as last assessed
- Active
- First seen
- Unrecorded
- Last seen
- Unrecorded
- Indicators
- 26
- Sources
- 1
- Targets
- macOS
- Fake software download page
- Technology company impersonation
- MacSync
- SHub Stealer
- Fake GitHub repository
Original research
- Datadog Security Labs2026-02-10Vendor researchFirst account
Tech impersonators: ClickFix and MacOS infostealers
This page summarises and structures that research; it is not a substitute for the original.
Researchers: if anything here misrepresents your work, email corrections@clickfixreport.com — we correct within 5 working days, no questions asked.
Summary
Datadog Security Labs described this operation on 10 February 2026 and assessed it as ongoing. GitHub repositories posing as desktop software from technology firms — one advertised a Datadog desktop application that does not exist — held only a README whose download link began a redirect chain. A GitHub Pages site styled after GitHub itself profiled each visitor, posted the fingerprint to a Google Apps Script address, and sorted traffic: macOS visitors reached a ClickFix page, Windows a ZIP download, others a genuine pricing page. The ClickFix page had the visitor paste a Terminal command that pulled a shell script and executed it. Earlier variants installed MacSync, formerly Mac.c, which swapped resources of installed wallet applications; later ones delivered SHub Stealer v2.0, which validates the phished password, gathers documents, browser and wallet data, and persists as a counterfeit Google updater beaconing for commands. Datadog reported the repositories to GitHub.
Overlap with other campaigns
We compared the 26 indicators in this record — covering 17 distinct registrable domains — against the 43 other published campaigns in this corpus.
SHub Stealer via macOS Terminal
2026-08-071 of the 26 indicators in SHub and MacSync via GitHub lures also appear in this campaign.
Kimsuky deploying QuasarRAT
2026-08-07No indicator is shared, but the two records use the same registrable domains.
Shared registrable domain (1)
- domain, shown defanged for safety: gmail dot com
A shared indicator is the same record cited by both campaigns. A shared registrable domain is weaker evidence and is counted separately, because two campaigns can share a registrable simply by renting subdomains from the same platform.
Execution mechanisms
How the pasted command actually ran, as the published accounts describe it. Every row under “Mechanism” is one this campaign records; “Across the corpus” is the share of the 44 published campaigns in this corpus that record the same one — a baseline we can only state because we hold the whole set.
| Mechanism | Across the corpus | ATT&CK |
|---|---|---|
| Clipboard injection | 15 of 4434% | T1204.004 |
| Terminal paste (macOS) | 8 of 4418% | T1059.004 |
Both of these mechanisms appear together in 2 of the 44 campaigns on record, this one included. We record a mechanism only where a source describes one: an absent mechanism means nobody wrote it down, not that it did not happen.
Indicators
26 indicators, each present verbatim in at least one of the sources above. Values are shown defanged and are not links to the hosts — the link goes to our page for that indicator. No observation date is recorded for any of them.
“Assessment” is who controls the host, not how dangerous it is. Many of these are compromised legitimate sites whose owners are victims, and they are excluded from every blocklist file we publish.
Not on this record
This record does not yet carry a second publisher's account or our own re-checks of these indicators. Each appears on this page as its own section once it exists; none of it is inferred.
Cite as
ClickFixReport, “SHub and MacSync via GitHub lures”, campaign ID 3c150b60, retrieved 2026-08-29, snapshot fb0eed7.
https://clickfixreport.com/campaigns/3c150b60/github-tech-impersonation-clickfix
Published under CC BY 4.0. Reuse it, including commercially, with attribution. The date above is when this record last changed, not when you opened it — the page is a versioned record, so that is the date a reader needs to find what you saw.