"Help, how do I remove this malware?" is a recurring post in Mac forums, and in 2026 it almost always traces back to the same thing: a fake CAPTCHA page that talks the visitor into opening Terminal and pasting a command. Security researchers call the technique ClickFix, and multiple campaigns using it against Mac users have been tracked throughout this year, including ones specifically targeting developers and AI tool users. This guide covers how it happens, what to do if you already ran a command, and how to check a Mac properly rather than guessing.

How Mac infections actually happen now

Mac malware rarely arrives through a software exploit anymore. The dominant technique in 2026 is social engineering, not a technical flaw:

  1. A fake verification page. You land on a site, often a compromised but otherwise legitimate WordPress site, and see what looks like a standard Cloudflare human-check or a "macOS optimization" prompt.
  2. It asks you to open Terminal and paste a command. Some variants copy the command to your clipboard automatically and walk you through Command+Space, open Terminal, paste, press Return.
  3. You run it yourself. Because you typed Return, not an attacker exploiting a bug, this sails past most traditional defenses. One campaign even clears the Terminal window afterward and prints a fake "Verification successful" message so you do not realize anything happened.
  4. The payload installs quietly. It typically downloads a file to a temporary folder, runs it in the background with a command like nohup so it survives closing Terminal, and begins collecting data.

No legitimate CAPTCHA, website, or verification system ever requires you to open Terminal and paste anything. That single fact covers the vast majority of current Mac infections. In March 2026, Apple added a mitigation to macOS specifically to warn users before this kind of command runs, but new variants keep finding ways around simple warnings, so the habit matters more than the patch.

If you already ran a Terminal command from a website

Treat the Mac as compromised right now, before you do anything else:

  1. From a different, clean device, change the passwords for your email, banking, and any account you use a password manager for.
  2. Check for the Macfinger indicator. If the path ~/Library/Caches/com.apple.metadata/com.apple.verified exists on your Mac, one security researcher flags it as a sign of this specific campaign.
  3. Disconnect from the network if you suspect active, ongoing exfiltration, then continue with the checks below.
  4. Do not trust Keychain prompts for a while. Some campaigns specifically try to harvest your Keychain password through a fake system dialog after the initial command runs. If you see an unexpected Keychain password prompt in the hours after this, cancel it and do not type anything.

Signs your Mac may be infected

  • Unexplained high CPU usage when the Mac is idle, visible in Activity Monitor.
  • Browser redirects, unexpected pop-ups, or a new default search engine you did not set.
  • Fake software update prompts appearing outside System Settings.
  • Login Items or background items you do not recognize.
  • A noticeably hotter Mac or louder fans with no obvious cause.

None of these alone proves an infection. Golden Gate's own post-upgrade indexing can also spike CPU and heat; see our System Data guide if storage looks unusually full at the same time. The check below is what actually confirms it either way.

Where Mac malware hides

Mac persistence techniques are well documented and cluster around a small number of locations:

LocationScope
/Library/LaunchDaemons/System-wide, runs at boot, before any login
/Library/LaunchAgents/System-wide, runs at login for any user
~/Library/LaunchAgents/Runs at login for your user only
Login Items & ExtensionsApps set to open automatically at login
Background ItemsApps allowed to run without appearing in the Dock
Browser extensionsPersist independently of the app itself
Configuration profilesCan enforce settings or install certificates without your ongoing awareness
Cron jobsScheduled tasks, less common but still used

How to check, step by step

  1. Activity Monitor. Open it, sort by CPU, and look for processes you do not recognize, especially ones with unusual or randomized-looking names.
  2. Login Items & Extensions. System Settings > General > Login Items & Extensions. Click anything you do not recognize and remove it. Check the "Allow in the Background" section on the same screen too.
  3. LaunchAgents and LaunchDaemons. Open Finder, press Command+Shift+G, and check each of these paths:
    /Library/LaunchDaemons/
    /Library/LaunchAgents/
    ~/Library/LaunchAgents/
    Look for unfamiliar .plist files, especially ones with generic or recently modified names.
  4. Configuration profiles. System Settings > General > Device Management, or Privacy & Security > Profiles depending on your macOS version. Remove any profile you did not install yourself.
  5. Browser extensions. Check each browser's extensions page individually and remove anything unfamiliar.
  6. Temporary files from the infection vector. If you ran a ClickFix-style command, check /tmp for recently created files you do not recognize.

Removing what you find

  1. Quit the suspicious app or process first, from Activity Monitor if it will not quit normally.
  2. Delete the app itself from the Applications folder.
  3. Delete the matching LaunchAgent or LaunchDaemon plist you identified above.
  4. Remove the Login Item or Background Item entry.
  5. Restart the Mac.
  6. Reopen Activity Monitor and Login Items & Extensions, and confirm nothing suspicious has reappeared.
  7. Over the next week, watch for the symptoms coming back: idle CPU spikes, browser redirects, fake update prompts, or new unfamiliar Login Items.

When a factory reset is the only real fix

Manual removal works for straightforward adware and browser hijackers. It is not reliable against a genuine infostealer that has already run with full user permissions, because you cannot be certain everything it touched, downloaded, or configured has been found and undone. If any of these apply, a clean erase and reinstall of macOS is the safer path:

  • You ran a Terminal command from a suspicious page, and the malware had time to run before you noticed.
  • You granted administrator password or Keychain access during a prompt you now believe was part of the attack.
  • Symptoms keep returning after you have removed everything you can find.
  • You handle sensitive data, credentials, or crypto wallets on the Mac. See our hot wallet threat model guide if that applies to you.

Back up your files (not your apps or system settings, which could carry the infection back with them), erase the disk from Recovery, and do a clean install.

After cleanup: close the door it came through

  • Never paste a command into Terminal from a website, no matter how it is framed. No legitimate verification process requires it.
  • If a page tells you your browser needs to "prove it's not a bot" in a way that involves Terminal, close the tab.
  • Keep Gatekeeper and XProtect enabled, and keep macOS updated. See which security update your Mac needs.
  • Before installing any app from outside the Mac App Store, check our guide on how to verify an app is genuine.

The short version

  • Most current Mac malware spreads through ClickFix: a fake CAPTCHA or verification page that tricks you into pasting a command into Terminal yourself.
  • If you already ran a command like that, change your important passwords from a different device immediately.
  • Check Activity Monitor, Login Items & Extensions, LaunchAgents and LaunchDaemons, and configuration profiles for anything unfamiliar.
  • For a genuine infostealer infection, a clean erase and reinstall is more reliable than manual removal.