New notnullOSX Malware Targets High-Value Crypto Wallets on macOS

New notnullOSX Malware Targets High-Value Crypto Wallets on macOS

First seen 11 Apr 2026, 17:19 UTC GbhackersScworldCybersecuritynewshackread.com 66.5

Article Content

Browse articles
ThreatCluster

The notnullOSX malware has emerged as a significant threat targeting cryptocurrency wallets with balances exceeding $10,000 in Taiwan, Vietnam, and Spain. This campaign, identified as ClickFix, was reported on March 30, 2026, and involves deceptive tactics using a fake Google Document and a compromised YouTube channel to distribute the malware. Users are tricked into executing commands in the macOS Terminal that download notnullOSX, which requires total disk access. The malware's most alarming feature is its ReplaceApp module, which substitutes legitimate Trezor or Ledger Live wallets with counterfeit versions to steal secret seed phrases in real-time. The malware's developer, known as 0xFFF or alh1mik, rejoined a hacking forum earlier this year after a three-year hiatus. The ongoing attacks raise concerns about the security of cryptocurrency assets among macOS users.

Key Points: • notnullOSX targets high-value cryptocurrency wallets on macOS systems. • Attackers use deceptive Google Documents and compromised YouTube channels for distribution. • The malware can replace legitimate hardware wallet software with counterfeit versions.

Timeline

2026-03-30
ClickFix campaign identified targeting crypto wallets.
2026-04-09
Gbhackers article published detailing notnullOSX.
2026-04-11
Scworld article published on notnullOSX malware.