Skip to content

Campaign record

SHub and MacSync via GitHub lures

Fake vendor GitHub repos funnel macOS users through ClickFix into MacSync and SHub

Status as last assessed
Active
First seen
Unrecorded
Last seen
Unrecorded
Indicators
26
Sources
1
Targets
macOS
  • Fake software download page
  • Technology company impersonation
  • MacSync
  • SHub Stealer
  • Fake GitHub repository

Original research

This page summarises and structures that research; it is not a substitute for the original.

Researchers: if anything here misrepresents your work, email corrections@clickfixreport.com — we correct within 5 working days, no questions asked.

Summary

Datadog Security Labs described this operation on 10 February 2026 and assessed it as ongoing. GitHub repositories posing as desktop software from technology firms — one advertised a Datadog desktop application that does not exist — held only a README whose download link began a redirect chain. A GitHub Pages site styled after GitHub itself profiled each visitor, posted the fingerprint to a Google Apps Script address, and sorted traffic: macOS visitors reached a ClickFix page, Windows a ZIP download, others a genuine pricing page. The ClickFix page had the visitor paste a Terminal command that pulled a shell script and executed it. Earlier variants installed MacSync, formerly Mac.c, which swapped resources of installed wallet applications; later ones delivered SHub Stealer v2.0, which validates the phished password, gathers documents, browser and wallet data, and persists as a counterfeit Google updater beaconing for commands. Datadog reported the repositories to GitHub.

Overlap with other campaigns

We compared the 26 indicators in this record — covering 17 distinct registrable domains — against the 43 other published campaigns in this corpus.

  • 1 of the 26 indicators in SHub and MacSync via GitHub lures also appear in this campaign.

  • No indicator is shared, but the two records use the same registrable domains.

    Shared registrable domain (1)

    • domain, shown defanged for safety: gmail dot com

A shared indicator is the same record cited by both campaigns. A shared registrable domain is weaker evidence and is counted separately, because two campaigns can share a registrable simply by renting subdomains from the same platform.

Execution mechanisms

How the pasted command actually ran, as the published accounts describe it. Every row under “Mechanism” is one this campaign records; “Across the corpus” is the share of the 44 published campaigns in this corpus that record the same one — a baseline we can only state because we hold the whole set.

Execution mechanisms recorded for this campaign, with their frequency across the corpus
MechanismAcross the corpusATT&CK
Clipboard injection15 of 4434%T1204.004
Terminal paste (macOS)8 of 4418%T1059.004

Both of these mechanisms appear together in 2 of the 44 campaigns on record, this one included. We record a mechanism only where a source describes one: an absent mechanism means nobody wrote it down, not that it did not happen.

Indicators

26 indicators, each present verbatim in at least one of the sources above. Values are shown defanged and are not links to the hosts — the link goes to our page for that indicator. No observation date is recorded for any of them.

Indicators recorded for this campaign, shown defanged
IndicatorTypeRoleAssessmentReport an error
domain, shown defanged for safety: drmcdermottmd dot comdomainLure pageNot yet assessedReport an error in domain record 128319e5-12cf-4854-b01b-3077d6190387
domain, shown defanged for safety: hci-outdoors dot comdomainLure pageNot yet assessedReport an error in domain record adee6ce9-b95e-416d-8774-50e00f01e9f2
domain, shown defanged for safety: skpwresorts dot comdomainLure pageNot yet assessedReport an error in domain record 364b63c4-5280-42ca-ae12-e36bef2c4354
domain, shown defanged for safety: tiptopmarine dot comdomainLure pageNot yet assessedReport an error in domain record 7872c251-5c62-49d7-ba56-eabbb4718eb3
domain, shown defanged for safety: warboardgame dot comdomainLure pageNot yet assessedReport an error in domain record 4e23e9b2-bfe8-4547-b0d6-709784fc5fef
url, shown defanged for safety: hxxps colon slash slash github dot com/Datadog-Desktop-AppurlLure pageShared platformReport an error in url record 435a58c8-adb8-4d4e-8557-65f0d8d3d61a
domain, shown defanged for safety: 3commas-app dot github dot iodomainRedirectorShared platformReport an error in domain record 7619af73-2cdb-49e9-add7-545dab527f43
domain, shown defanged for safety: git-tool-install dot github dot iodomainRedirectorShared platformReport an error in domain record 89ecb83d-8753-47e6-85ec-8a2c054c0545
domain, shown defanged for safety: io-app-git dot github dot iodomainRedirectorShared platformReport an error in domain record d4493069-2f69-4d2e-a488-ba780ac3d14e
domain, shown defanged for safety: quadency-pro dot github dot iodomainRedirectorShared platformReport an error in domain record cf5ae853-eb5e-4771-8d2c-e3ef143a6a49
url, shown defanged for safety: hxxps colon slash slash pmacos dot onelink dot me/m5yY/q5vbjgvhurlRedirectorShared platformReport an error in url record 3137a8f7-daf4-4b4e-8818-58ec6f35ebbf
url, shown defanged for safety: hxxps colon slash slash pwin dot onelink dot me/zmFc/dt38769zurlRedirectorShared platformReport an error in url record 61644074-21c4-40fa-b9e6-8e7c08e3fa48
domain, shown defanged for safety: imper-strlk5 dot comdomainCommand and controlAttacker-controlledReport an error in domain record 5eac68e0-8bce-4614-8450-e327f30fc017
domain, shown defanged for safety: mini-zmoto dot comdomainCommand and controlAttacker-controlledReport an error in domain record f7e69398-4960-4bff-babd-e091b830b592
domain, shown defanged for safety: mubasokurso dot comdomainCommand and controlAttacker-controlledReport an error in domain record 27c82fcf-231f-42d7-a76c-be594a7dbdd0
domain, shown defanged for safety: securityfenceandwelding dot comdomainCommand and controlNot yet assessedReport an error in domain record 6f048ac0-3726-4e6a-8dab-6719b420f1e8
domain, shown defanged for safety: stobminipinporl dot comdomainCommand and controlAttacker-controlledReport an error in domain record 6ef0213b-e98c-436e-a6d0-b733c47d0bf9
sha256, shown defanged for safety: 9191101893e419eac4be02d416e4eed405ba2055441f36e564f09c19cb26271csha256SampleNot yet assessedReport an error in sha256 record 04a4a0b6-9edb-481d-9613-d6f5bb8ac927
email, shown defanged for safety: briandaem3440 at hotmail dot comemailOtherNot yet assessedReport an error in email record be44bba0-e930-4338-9213-3200878da1ec
email, shown defanged for safety: esztersa7536 at hotmail dot comemailOtherNot yet assessedReport an error in email record 48a1f368-309c-4f53-96d6-f75af5eb00a7
email, shown defanged for safety: mayleeneslyn7391 at outlook dot comemailOtherNot yet assessedReport an error in email record 560d30ac-157f-4f17-989f-c312932309c5
email, shown defanged for safety: soocalicutt2358801 at gmail dot comemailOtherNot yet assessedReport an error in email record 713b1e60-f9d8-4701-9237-8310259ee5e5
email, shown defanged for safety: vlsgtric39151b at hotmail dot comemailOtherNot yet assessedReport an error in email record c0f588f0-f463-414a-833f-542cf324c170
filename, shown defanged for safety: ~/Library/Application Support/Google/GoogleUpdate dot app/Contents/MacOS/GoogleUpdatefilenameOtherNot yet assessedReport an error in filename record ef4a189b-5b9f-4b7e-bfc4-e4cd45df663c
filename, shown defanged for safety: ~/Library/LaunchAgents/com dot google dot keystone dot agent dot plistfilenameOtherNot yet assessedReport an error in filename record 7ebfa150-2f8c-4964-9811-7df3a14f558d
url, shown defanged for safety: hxxps colon slash slash script dot google dot com/macros/s/AKfycbwip_VgPEumBXeWuX_OEX6huIMHfPXidiweHpHR-fGUQIqpcR-mAMAHC1JCUQyJne3n0Q/execurlOtherShared platformReport an error in url record 655316a6-29e8-4256-a507-ae54fa8708de

“Assessment” is who controls the host, not how dangerous it is. Many of these are compromised legitimate sites whose owners are victims, and they are excluded from every blocklist file we publish.

Not on this record

This record does not yet carry a second publisher's account or our own re-checks of these indicators. Each appears on this page as its own section once it exists; none of it is inferred.

Cite as

ClickFixReport, “SHub and MacSync via GitHub lures”, campaign ID 3c150b60, retrieved 2026-08-29, snapshot fb0eed7.

https://clickfixreport.com/campaigns/3c150b60/github-tech-impersonation-clickfix

Published under CC BY 4.0. Reuse it, including commercially, with attribution. The date above is when this record last changed, not when you opened it — the page is a versioned record, so that is the date a reader needs to find what you saw.