macOS · contained automatically
An infostealer on a designer's Mac, contained in under three seconds
At 2:14 in the morning, someone at Acme Design pasted a “fix” from a web page into Terminal. Nobody was watching, and nobody needed to be.
- The command downloaded a script and piped it straight into a shell.
- The script installed a LaunchAgent named
com.apple.crashreporter.helper, pointing at an unsigned program in a hidden folder. - That program read Chrome's Safe Storage key from the Keychain, the step that turns stolen browser data into readable passwords, and connected out on an uncommon port.
- Scouter suspended both processes, quarantined the LaunchAgent, disabled its job and blocked the address, following the playbook for each alert.
- The analyst confirmed the chain from the timeline, isolated the Mac while the user's browser sessions and passwords were reset, and checked every other machine for the same LaunchAgent.




