Bybit Uncovers macOS Malware Campaign
Analysis based on 7 articles · First reported Apr 21, 2026 · Last updated Apr 21, 2026
The disclosure by Bybit highlights the increasing cybersecurity risks in the cryptocurrency sector, particularly from sophisticated malware campaigns targeting developers. This event could lead to increased investment in cybersecurity measures by other cryptocurrency exchanges and AI tool providers, potentially boosting the cybersecurity industry. For Bybit, this disclosure enhances its reputation as a leader in cybersecurity intelligence within the crypto space.
Bybit's Security Operations Center (SOC) uncovered a sophisticated, multi-stage malware campaign targeting MacOS users searching for 'Claude Code', an AI-powered development tool from Anthropic. The attackers used search engine optimization (SEO) poisoning to direct users to a spoofed installation page, deploying a two-stage malware chain. The initial payload, a Mach-O dropper, installed an infostealer to extract sensitive data including browser credentials, MacOS Keychain entries, Telegram sessions, VPN profiles, and cryptocurrency wallet information. A second-stage payload introduced a C++-based backdoor for persistent system access and remote command execution. Bybit leveraged AI-assisted workflows for rapid analysis, mitigation, and detection, completing these measures within the same day of identification on March 12, 2026. Public disclosure followed on March 20, 2026, with detailed detection guidance. The incident underscores a growing trend of attackers targeting developers through manipulated search results as AI tools gain mainstream adoption.
Set up alerts, explore entity relationships, search across thousands of events, and build custom intelligence feeds.
Open Dashboard