Bitcoin-Stealing Mac OS X Trojan Discovered

by

bitcoinA new Mac OS X trojan horse that monitors web browsing traffic in order to steal Bitcoins has been discovered by SecureMac. The trojan, called OSX/CoinThief.A, is disguised as an innocuous Bitcoin app called StealthBit that purports to send and receive anonymous payments.

The app was posted on open-source website GitHub, but the precompiled version of the app had the malicious payload installed. The malware installs browser extensions in Safari and Google Chrome looking for login credentials for a number of Bitcoin related websites including MtGox, BTC-e, and blockchain.info. When the app finds login credentials, it sends those back to the malware's developer.

Initial infection occurs when a user installs and runs an app called "StealthBit," which was recently available for download on GitHub, a website that acts as a repository for open source code. The source code to StealthBit was originally posted on GitHub, along with a precompiled copy of the app for download. The precompiled version of StealthBit did not match a copy generated from the source code, as it contained a malicious payload. Users who downloaded and ran the precompiled version of StealthBit instead ended up with infected systems. A user posting over the weekend on Reddit, the popular discussion site, reported losing 20 Bitcoins (currently worth upwards of $12,000 USD) to the thieves.

Bitcoin users who may have downloaded the app should check their browser extensions in Safari and Google Chrome for generic "Pop-Up Blocker" extensions.

Top Rated Comments

(View all)
Avatar
88 months ago

GitHub blew it. They should check all packages before hosting them.

Yes, GitHub should check the million lines of code and the hunderds of packages uploaded every second to make sure there isn't any malicious code in there.

If you don't know what you're talking about, just don't say anything.
Score: 17 Votes (Like | Disagree)
Avatar
88 months ago

but i thought if i got my mac i wouldn't any viruses! darn pc vs mac commercials.


You're willingly turning over your login and pass and admin access to your computer. No operating system in the world will stop this type of thing from gain access when you hand it the keys. It's not your security systems fault if you give the burglar your alarm code.
Score: 12 Votes (Like | Disagree)
Avatar
88 months ago
So the user has to download and install the malware.
Score: 11 Votes (Like | Disagree)
Avatar
88 months ago
This type of Trojan horse always reminds me of the joke when viruses were first becoming popular. Sanitized to be PC...

XXXXX Virus:
You have just received the "XXXXXX Virus." As the we have no
programming experience, this virus works on the honor system.
Please delete all the files on your hard drive and manually forward
this virus to everyone on your mailing list.

Thank you for your cooperation,
XXXXXXX
Score: 9 Votes (Like | Disagree)
Avatar
88 months ago
It's not a virus...blah blah blah. Every time.
Score: 9 Votes (Like | Disagree)
Avatar
88 months ago

but i thought if i got my mac i wouldn't any viruses! darn pc vs mac commercials.


That's about as good as NBC's "All visitors to Sochi Immediately Hacked" claim:



Their claims were thoroughly debunked in the article That NBC story 100% fraudulent (http://blog.erratasec.com/2014/02/that-nbc-story-100-fraudulent.html). If I were Putin, I would have ejected the "journalist" who filed that story. :rolleyes:
Score: 7 Votes (Like | Disagree)

Top Stories

'A New iOS Update is Now Available' Popping Up Repeatedly in iOS 14 Beta [Fixed: New Beta Available]

Thursday October 29, 2020 6:11 pm PDT by
Many users running iOS 14 beta are reporting that they are seeing a dialog box pop up repeatedly asking them to update from the latest iOS 14 beta. Threads in our forums, Reddit, and Twitter are reporting the issue. The dialog has been appearing for a few days now, but as of tonight has started appearing more frequently, every time an iPhone is unlocked. There's been further discussion in...

Apple Seeds New iOS 14.2 Versions Which Stops 'New iOS Update Available' Alerts

Friday October 30, 2020 1:09 pm PDT by
Apple today seeded "Release Candidate" versions of upcoming iOS 14.2 and iPadOS 14.2 updates to developers and public beta testers, 10 days after seeding the fourth betas and a month and a half after releasing the iOS 14 and iPadOS 14 updates. iOS and iPadOS 14.2 can be downloaded by developers through the Apple Developer Center or over the air after the proper developer profile has been...

Apple One is Now Available: Save Money by Bundling Apple Music, iCloud Storage, Apple TV+, Apple Arcade, and More

Friday October 30, 2020 7:47 am PDT by
Apple One bundles are now available in the United States and over 100 other countries, allowing customers to subscribe to multiple Apple services through a single plan, including Apple Music, Apple TV+, Apple Arcade, iCloud, and more. To sign up for Apple One on an iPhone: Open Settings App Tap on Your Name at the top Tap on Subscriptions Tap on Apple One The prompt for Apple One...

Black Friday Spotlight: Best Buy Kicks Off a Month of Apple Deals and More

Friday October 30, 2020 10:02 am PDT by
We've begun tracking early Black Friday deals in our dedicated Black Friday Roundup, and in an effort to prepare our readers for the big shopping event we're highlighting sales store-by-store in the lead-up to November 27. Note: MacRumors is an affiliate partner with Best Buy. When you click a link and make a purchase, we may receive a small payment, which helps us keep the site running....

Apple Launches AirPods Pro Service Program for Crackling/Static Problems and ANC Issues

Friday October 30, 2020 3:03 pm PDT by
Apple today announced the launch of a new service program for AirPods Pro sound issues, which is designed to address AirPods Pro units experiencing static or crackling sounds or problems with Active Noise Cancellation. Faulty AirPods exhibit the following problems, according to Apple:Crackling or static sounds that increase in loud environments, with exercise or while talking on the phone ...

Apple CEO Tim Cook: 'More Exciting Things' in Store For This Year

Thursday October 29, 2020 2:20 pm PDT by
During today's earnings call for the fourth fiscal quarter of 2020 (third calendar quarter), Cook said that while he doesn't want to give too much away, "this year has a few more exciting things in store." Cook is likely speaking about the Apple Silicon Macs, as Apple has previously said the first Apple Silicon Mac will be coming before the end of 2020. There are rumors of a third fall event ...

Hands-On Comparison: iPhone 12 vs. iPhone 12 Pro

Friday October 30, 2020 2:29 pm PDT by
For those still trying to make a decision between an iPhone 12 or an iPhone 12 Pro, we picked up both models and in our latest YouTube video, did a hands-on comparison between them. Our video highlights the similarities and the differences so you can which one is the best fit for you and whether the iPhone 12 Pro is worth an extra $200. Subscribe to the MacRumors YouTube channel for more ...

Apple One Service Bundles Set to Launch Tomorrow, Fitness+ Coming This Quarter

Thursday October 29, 2020 1:39 pm PDT by
Apple in September announced Apple One, a new series of services bundles that will let Apple device customers purchase several services together in one package instead of separately, saving money for those who use multiple Apple service products. Ahead of Apple's earnings call, Apple CFO Luca Maestri told Bloomberg that Apple One is set to launch on Friday, October 30. Apple One Bundle...

PSA: Apple One Premier Bundle Only Available in US, UK, Canada, and Australia

Friday October 30, 2020 2:39 am PDT by
Apple's new Apple One series of services bundles launches on Friday in over 100 countries and regions, but the top Premier tier will be limited to the United States, the United Kingdom, Australia, and Canada. The limited rollout of the $29.95 Premier tier is down to the fact that Apple News+ is currently only available in the above countries. Apple News+ is exclusive to the Premier tier,...

Apple Says Record 2020 Mac Sales Attributed Primarily to MacBook Pro

Friday October 30, 2020 12:24 pm PDT by
Apple on Thursday reported its earnings for the fourth quarter of the 2020 fiscal year, including Mac revenue of $9 billion, a new quarterly record. Apple ended the year with annual Mac revenue of $28.6 billion, an all-time high. In its annual Form 10-K report [PDF], filed with the U.S. Securities and Exchange Commission today, Apple said increased Mac sales in fiscal 2020 compared to fiscal ...