Another MacOS malware is in the wild, dubbed ClickLock as it combines ClickFix + Locker technique. This malware will forced you to enter your login password as it will terminate all visible processes.
And it targets the following:
- 8 web browsers
- 31 cryptocurrency wallet browser extensions
- 7 password manager extensions
- 8 desktop cryptocurrency wallet applications
- Blockchain addresses across 6 different networks
- macOS Keychain
- Shell history
- FTP credentials
And base on their findings, their lure their victims thru ClickFix, that trigger a fake Cloudflare “human verification” sequence with an animated progress bar. And then after that, keyboard are being disabled and the malware modules are being downloaded from the background.

After the module has been executed, it will display a fake password dialog box. And if the users enters his data, exfiltrates it to the attacker via Telegram.
So again, with this recent spat of attacks on MacOS users, we need to be very vigilant time and time again.
https://www.group-ib.com/blog/clicklock-stealer-macos-malware/