A sophisticated malware strain dubbed Reaper has been identified targeting macOS users through deceptive application download pages. Security researchers have discovered that the malicious software specifically aims to compromise cryptocurrency wallet data, browser credentials, and sensitive personal documents. By exploiting native system tools, the malware attempts to bypass traditional security perceptions, posing a significant risk to investors utilizing desktop-based cold and hot storage solutions.
Exploitation of AppleScript and Social Engineering
The Reaper malware propagates via fraudulent websites masquerading as legitimate download portals for popular software such as WeChat and Miro. Once a user interacts with the site, the malware utilizes AppleScript URLs to trigger the built-in macOS Script Editor. To evade detection by automated security scanners, the attackers hide the malicious code using ASCII art and extensive spacing, making the script appear benign or corrupted at first glance.
AppleScript is a scripting language created by Apple that allows users to directly control scriptable Macintosh applications and parts of the macOS itself.
After the initial execution, the malware employs a social engineering tactic by displaying a fraudulent Apple security update pop-up. This window prompts victims to enter their system administrator password, granting the malware the elevated permissions necessary to access protected directories and modify system files.
Impact on Hardware Wallets and Browser Security
The primary objective of Reaper is the exfiltration of digital assets and private data. The malware specifically targets prominent desktop cryptocurrency interfaces, including:
- Ledger Live (Hardware wallet interface)
- Trezor Suite (Hardware wallet interface)
- Exodus (Multi-asset software wallet)
By modifying the internal code of these applications, Reaper can intercept future transactions and redirect funds to attacker-controlled addresses. Beyond crypto-specific targets, the malware harvests saved credentials from web browsers such as Chrome, Firefox, and Microsoft Edge, while also scanning the user's Desktop and Documents folders for sensitive files.
As of June 9, 2026, security experts recommend that macOS users exercise extreme caution when downloading software from third-party sources. To mitigate the risk of infection, it is advised to verify the authenticity of installation packages and utilize multi-signature hardware setups where possible. Maintaining up-to-date antivirus definitions and remaining vigilant against unexpected password prompts remains a critical defense against evolving threats like Reaper.
Frequently Asked Questions
Quick answers to the most common questions about this topic.