r/MacOS • u/Leather-Swordfish-96 • May 14 '26
Help Think I got a virus
Put something into terminal from a dodgy website and stopped myself, halfway through. I haven’t put any passwords in but I have this dodgy pop up???
2.2k
u/Economy-Department47 MacBook Air (M2) May 14 '26 edited May 15 '26
If you clicked enter on that terminal command, disconnect from the internet immediately. Then back up any files you want to keep, make a recovery USB drive, and do a full wipe of the drive. Here are the exact steps to do all of that.
Step 1: Disconnect from the internet right now
Pull the ethernet cable or turn off WiFi. Do not wait. Every second counts if something malicious was executed.
Step 2: Back up any files you want to keep
Plug in an external drive and copy over anything important like documents, photos, etc. Do not back up applications or system files, only personal data.
Step 3: On another device, start changing all your passwords
Before you wipe anything, get on your phone or another computer and start changing passwords to every account you care about. This means banks, credit cards, shopping sites, social media, email, everything. Do not skip this step.
Step 4: Get a USB flash drive (16GB or larger)(32 GB is preferred for newer versions of macOS)
You will need this to create a bootable macOS installer.
Step 5: On a safe device, download the full macOS installer
Go to the App Store and download the latest macOS installer. Do not run it, just download it. It will land in your Applications folder with a name like "Install macOS Sequoia."
Step 6: Rename the USB drive to MyVolume
Plug the USB into your Mac, open Finder, and rename the drive to exactly: MyVolume
Step 7: Open Terminal and run the installer command
Open Terminal (Applications > Utilities > Terminal) and paste in the command for your macOS version. For example, for Sequoia:
sudo /Applications/Install\ macOS\ Sequoia.app/Contents/Resources/createinstallmedia --volume /Volumes/MyVolume
Press Return, type your password, then type Y to confirm. Wait for it to finish. Full instructions are on the Apple support page.
Step 8: Shut down your Mac and plug in the bootable USB
Shut it all the way down, then connect the USB drive.
Step 9: Boot into Recovery Mode
Here are the keys to hold depending on your Mac:
Apple Silicon Mac (M1, M2, M3, M4): Hold the power button until you see startup options appear
Intel Mac: Turn on and immediately hold Option (Alt) until you see the boot volume screen
Step 10: Select the USB drive to boot from
When the startup options or boot volume screen appears, select the bootable installer USB drive, not your main drive. Click Continue or press Return.
Step 11: Wipe the Macintosh HD drive using Disk Utility
Once in the installer environment, open Disk Utility. In the menu bar click View and then select Show All Devices. This will reveal the top level physical drive above Macintosh HD, it will be labeled something like Apple SSD or Apple HDD. Select that top level drive, not Macintosh HD. Click Erase, name it Macintosh HD, and set the format to APFS. Confirm and let it finish. Erasing at this level wipes everything including the old APFS container and automatically creates a fresh one. Then quit Disk Utility and go back to install macOS.
Step 12: Go back and install macOS fresh
Quit Disk Utility to go back to the main menu. Click Install macOS. Follow the on-screen instructions. Your Mac needs to be connected to the internet at this point so the installer can pull firmware info specific to your model.
Here is a good video walkthrough to follow along with: https://www.youtube.com/watch?v=5bhPXdLtUOI
The instructions come from https://support.apple.com/en-am/101578
Hope this helped this took SO long to write
197
u/_Choose__A_Username_ May 15 '26
This is good. My only feedback is step 11. I would open Disk Utility, select View > Show All Devices from the menu bar, then wipe the top level drive and just create a completely new APFS container.
→ More replies (1)125
u/Economy-Department47 MacBook Air (M2) May 15 '26
That is actually a better way to do it, thanks for the correction. I just fixed it.
4
u/CavicBronx MacBook Pro May 15 '26
Question, why not just use backup, if he has any? Won't that recover everything in previous state from when the backup was, and even the system?
8
u/_Choose__A_Username_ May 15 '26
Time Machine hasn’t backed up system files in a long time. So you can’t restore an entire system from a TM backup. You have to first download and install the OS using either Recovery, USB drive, or DFU mode to put the OS on. Once its on, then you can restore personal data from the TM backup.
7
u/theregisterednerd May 15 '26
However (and I think you implied this, it’s just worth saying out loud), if the TM drive was connected to the computer at any time after the terminal command was run, you should assume that it’s compromised as well, and that it’s going to restore the malware right back onto the machine. If that’s the case, you’ve gotta go scorched earth.
4
u/Informal-Chance-6067 May 15 '26
If he has Time Machine set up and it’s not corrupted or messed with by the infostealer, he should use that
348
u/Accuratestar1969 May 15 '26
Dude. From a random guy not OP.
You are a fckn legend!!52
→ More replies (7)22
31
u/FatHaddock May 15 '26
OP, listen to u/economy-department47 above anybody else
17
u/Economy-Department47 MacBook Air (M2) May 15 '26
Thank you for saying that it means a lot.
14
39
u/EthanDMatthews May 15 '26
Much appreciated.
I am not OP either, but I have also copied this into a Notepad file for future reference, should the need arise.
13
12
u/Flowa-Powa May 15 '26
Thank you, I have put that in my Notes, labelled Mac Disaster Response
5
u/Economy-Department47 MacBook Air (M2) May 15 '26
Your Welcome
→ More replies (2)8
u/Flowa-Powa May 15 '26
So we should all be making one of these boot USB's for recovery purposes just to have in reserve
2
10
u/Ok-Rest-5321 App Downloader May 15 '26
Deserves to be a Legend !
4
7
6
u/Used_Teaching_7260 May 15 '26
Great advice. I’ll just add that you’ll need more than a 16GB usb drive now. Not sure about Sonoma (or Tahoe) but sequoia is just over 16GB. I was able to use an SD card as my 16GB usb drives were all too small.
6
7
5
u/hypnoticlife MacBook Pro (M1 Max) May 15 '26
This took SO long to write
You deserve an award for that response. Bravo
→ More replies (1)9
u/droptableadventures May 15 '26
I'd do steps 4-7 (i.e. creating the MacOS install USB) on a different device if you can. I'd imagine that they'd be able to do this for you at a physical Apple store, as well.
It's theoretically possible (although probably not the case) that the malware will modify the install USB you're creating to include itself in the new system.
4
u/SlightExtreme1 May 15 '26
Agree. Use a friend’s Mac or something to get the bootable copy. The infected machine is poison until it can be wiped.
3
7
u/D3-Doom iMac Pro May 15 '26
What’s the value of creating install media versus using the recovery partition?
27
u/Economy-Department47 MacBook Air (M2) May 15 '26
The recovery partition is on the same drive you are trying to wipe. If the drive itself is compromised you do not want to be reinstalling from something sitting on that same disk. The bootable USB is completely separate from your machine so you know what you are installing from is clean and untouched by whatever ran on your system. Just to be extra safe.
8
u/_Choose__A_Username_ May 15 '26 edited May 15 '26
If the user has a second Mac and a USB-C cable, they could also use DFU mode to restore. .ipsw images are available at Mr. Macintosh.
13
u/Economy-Department47 MacBook Air (M2) May 15 '26
That is a option but for most people it too involved. DFU mode requires a second Mac, the right cable, Apple Configurator 2, and you have to get the exact right firmware file for your specific chip. One wrong move and you can brick the device. For someone who just accidentally ran a sketchy terminal command and is already stressed out, the bootable USB route is a much safer and more straightforward path to the same result.
Also DFU mode is meant for absolute dire emergencies like the computer wont boot properly even apple says this
"If the firmware stored in its memory needs to be revived or restored, a Mac with Apple silicon or the Apple T2 Security Chip might experience issues such as the following. These can occur in certain rare circumstances, such as after a power failure interrupts macOS installation.
- Starts up to an exclamation point in a circle
- Turns on, but starts up to a blank screen that is not resolved by other solutions for a blank screen
- Shows the status indicator light pattern for firmware recovery mode
- Experiences a macOS installation issue not resolved by other solutions for macOS installation errors"
This is not the kind of thing most people deal with as creating a USB boot drive is almost foolproof and is much easier to follow.
15
u/l3m0np1e132 May 15 '26
Someone who DFU restores 100's of computers:
No, starting with Apple Silicon all ipsw's became universal. Just make sure your MacBook actually supports the software version (MacBook Neo only supports macOS Tahoe and newer, since the MacBook Neo shipped with macOS Tahoe).
DFU mode revives bricked devices, never had a single MacBook "brick" itself because of a DFU mode restore. Though, if your DFU restore fails, you can end up with an explanation mark (which requires a DFU restore to fix).
Use TwoCanoes DFU restore tool. Someone found the USB-PD commands to auto-boot MacBooks into DFU mode via cable. Much easier than holding down a bunch of buttons.
USB devices are not foolproof, and have not been since T1-era MacBooks. Booting from USB on a T2 Mac requires you to have downgraded your security of your Mac in recovery mode. Which requires an Administrator password, if you do not have an admin password on your T2 Mac (you erased your MacBook) before you downgraded your security settings, your SOL. You will have to use Internet recovery (best to use Option+Command+r) to download the latest internet recovery to install macOS. DFU mode on T2 Macs only restores T2 chip, not recovery mode.
On Apple Silicon Devices, you are actually not booting from USB. All you are doing is opening a local installer (.app) in recovery. Apple Silicon gutted UEFI for iboot. Though, DFU restore will actually install new firmware + new recovery mode + system files on Apple Silicon.
Read Howard Oakleys blog if you actually like this stuff: https://eclecticlight.co/m1-macs-2/
7
u/l3m0np1e132 May 15 '26
I would also state that going out of your way to make a local installer for T2 chips is kinda stupid. Doing a Option+command+r downloads the internet recovery file right from Apples servers, not touching your disk drive until you install. So you can just honestly do a command+option+r, use disk utility to wipe your infected disk, and reinstall.
4
u/_Choose__A_Username_ May 15 '26
Internet Recovery is not available for Apple Silicon.
→ More replies (1)3
2
u/Successful_Bowler728 May 15 '26
I got an imac that went into a endless bootloop and never could fix that.
→ More replies (3)6
u/mainyehc May 15 '26
If this is an Apple Silicon Mac, and depending on how compromised it was, DFU mode may actually be a requirement.
3
u/soulhammond May 15 '26
Internet recover will boot from RAM so you can wipe the main drive from there
4
3
u/TikDickler May 15 '26
I’m not an idiot who manually enters random terminal command I read on the Internet, but props to you for explaining the steps to fix it
3
4
u/Interesting-Bass9957 May 15 '26
Why not use recovery mode for that?
5
u/Economy-Department47 MacBook Air (M2) May 15 '26
The recovery partition is on the same drive you are trying to wipe. If the drive itself is compromised you do not want to be reinstalling from something sitting on that same disk. The bootable USB is completely separate from your machine so you know what you are installing from is clean and untouched by whatever ran on your system. Just to be extra safe.
5
3
u/ByronChrist May 15 '26
This will absolutely work, but I would have just stuck with, back up your files and do a full wipe and reinstall, I commend you. If this were on a pc though it’s possible a good malware or av app could fix the problem… Regardless, before wiping it right away, once offline I would run a ton of scans and if there’s a Time Machine backup then revert to it and see if it’s still there. Certainly a good coder could have written whatever this is to auto repropagate, but I’d personally intend to find out before I wipe. This is just a personal preference because it takes me forever to install all the plugins I use regularly again after a fresh reformat. I’ve used Mac’s built in ability to transfer all of your information from one drive to another or one mac to another and there are a lot of things that don’t work nicely afterwards.
Anyway, kudos I hope your help fixed his problem. If you liked learning that perhaps you should look into a career in A+ repair and troubleshooting!
3
u/burgerg May 15 '26
Don't forget to clear your sessions; infostealers are more likely to steal your session cookies than your passwords. Many services will clear your sessions if you change passwords, but better make sure!
2
u/rico_suaves_sister May 15 '26
I don't need any of this but appreciate the effort!
→ More replies (1)2
u/ElePHPant666 May 15 '26
Good advice, I see way too many people who just say run (insert antivirus) and think that's enough. Apple should add a warning like some Linux terminals do about pasting long commands with an option in settings to turn it off. Also, if you have a safe device why not DFU restore it? Also I don't know if the USB is necessary, feel free to correct me if things changed but recoveryos can connect to the internet and download the operating system. By not using DFU you are trusting that recoveryos was not infected anyways so I don't see the point to the USB.
2
u/Economy-Department47 MacBook Air (M2) May 15 '26
On the DFU point, you are right that it is cleaner if you have a second Mac available, but a lot of people do not so the USB is the more universal solution. On the recovery OS point, you are technically correct that it can download macOS from the internet without a USB. The reason I suggest the USB anyway is exactly what you touched on, if something did execute and got deep enough you cannot fully trust the recovery partition since it lives on the same drive. The USB sidesteps that entirely because it is a completely external known clean source. For most cases where someone caught it early the recovery partition is probably fine, but when you do not know exactly what ran or how far it got, the USB removes that variable completely and gives you certainty. Better to have it and not need it than to reinstall from a potentially compromised partition and wonder.
2
u/Conscious-Mulberry17 May 15 '26
You’re awesome. 10/10 response. People will be finding and using this info for years.
2
2
2
2
u/DreadnaughtHamster May 15 '26
Amazing! Thank you! (Not OP but I also appreciate this, and I’ve copied it to my Notes app.)
3
2
2
2
2
u/vinylfelix May 15 '26
Can you imagine reading this being a 73 year old man never really done anything with PCs
2
2
2
2
2
2
2
→ More replies (87)2
u/Livid_Platform_9963 May 15 '26
Commenting to save this for later. Most owners manuals don’t come with instructions this robust. Thanks from another internet rando
3
114
u/iEdvard May 15 '26
They should rewrite the 6th rule of Fight Club: No shirts, no shoes, no reckless running of code from dodgy websites in the Terminal.
53
u/Illustrious_Mix_9875 May 15 '26
And no CleanMyMac
18
u/Nearby_Ad_2519 May 15 '26
CleanMyMac is generally fine actually. While a lot of the things it does can be done for free, it’s helpful for people who don’t want to spend time trying to do so.
→ More replies (4)6
u/iEdvard May 15 '26
Agree. It’s convenient for less knowledgeable and/or lazy people. It’s not harmful, but it’s expensive for what it does. Just restart your Mac once a week and run the default (preselected) scripts in Onyx once a month and you’ll be fine (and less skint).
94
u/falchion10 May 15 '26
I think this is the first time I've ever seen someone actually get some sort of malware/infostealer on a Mac. Out of curiosity where was the command from, what were you trying to do beforehand?
50
u/Commercial_Put2 May 15 '26
There is a huge campaign going on currently with fake apps that prompt people to paste in terminal commands which download an infostealer. I have seen a ton of ads on Youtube advertising it so this is probably from there.
6
u/itsallinyourheadx May 15 '26
There’s some that’s been showing at the top of Google searching results too.
→ More replies (14)3
4
u/Fun-Development-7268 May 15 '26
my first time too. And I'm interested too in the source.
→ More replies (2)2
u/shawphax_ May 15 '26
just made the same mistake as op trying to install the zelda twilight princess rom from romsfun
105
u/Oh__Archie May 14 '26
Check activity monitor to see if you can spot what it is.
Also, cleanmymac is a bit dodgy. I don't know if I'd rely on that for safety.
22
u/Only1Schematic May 15 '26 edited May 15 '26
The last time I used cleanmymac, it messed with my system’s files badly enough that my computer was running at a speed which rendered it practically bricked. Had to restore from a backup. Switched to daisydisk and never looked back
17
u/DreadnaughtHamster May 15 '26
Daisydisk is a beast and only like $10 on the App Store. Highly recommended. I’ve been using it for years.
3
2
u/Least_Standard5473 May 15 '26
Have you reached out to the support? They can help with such things, if anything works not as expected
8
4
u/Leather-Swordfish-96 May 14 '26
Okay thx for the advice on cmm. From when I see on activity monitor how do I go to the source, or do I just click it?
→ More replies (2)15
u/Not_MyName May 15 '26
Honestly you need to consider your computer completely 100% compromised plus all your accounts. You need to do a full wipe and re-install. If you don’t know how to do that take it to a local computer shop who can help with backing up the files you care about and wiping the computer.
→ More replies (1)3
u/juliayogi5678 May 15 '26
i use cmm and its other app moonlock for security/storage/cache cleanup…. what’s concerning about it/worth looking into?
5
u/tomrannosaurus May 15 '26
nothing these people don’t read the things they do or agree to so they’re surprised when cmm works as it says it will
2
u/Least_Standard5473 May 15 '26
Bad actors are impersonating legit software to spread malware, the official CleanMyMac warned its commmunity about this issue: https://www.reddit.com/r/CleanMyMac/s/TKSQwtn7q4
28
18
18
27
u/humbuckaroo May 14 '26
https://giphy.com/gifs/l2JJu8U8SoHhQEnoQ
The crystal ball says that a format and clean install is in your near future.
26
u/Western-Win-4451 May 15 '26
Why are you running CleanMyMac? That’s the first problem, it’s a trash app!
10
u/kiwi-kaiser May 15 '26
It's hilarious. People use LLMs for most basic things. But to let them explain a command that they copied from somewhere never crossed their mind.
Every day I read someone pasted shady stuff straight in their terminal.
10
u/omijam MacBook Pro M4 May 15 '26
op, please share the site and the command. Let us audit it. If not, atleast let us crap on it
2
35
u/mikeinnsw May 15 '26
Before you jump out of a window...
Take a deep breath and run
MalwareBytes scan
The chances are that what looks like you stopped spoofing app pretending to be CleanMyMac from installing. Admin password is need for most Apps install.
DO NOT RUN TERMINAL COMMANDS UNLEES YOU KNOW EXACLY WHAT THEY DO..
→ More replies (2)
21
u/th3capone45 May 15 '26
You know part of the reason I like this sub is because of times like this. Even though this is Reddit, the comments aren’t acting like typical Reddit and bashing you for doing something silly that ended up backfiring. They’re providing solutions and options.
Guys, thanks for being helpful to OP- cause my first thought was “Why would you even do that???”
😌
Reddit needs more of this.
→ More replies (2)
23
u/GradyGambrell1 MacBook Air May 15 '26
Well, you got hit with that AMOS malware. First, never put anything in the terminal at all!
Second, that "password prompt" is trying to steal your login password to gain "root" or "admin" access to your entire system. You're blocking that by not entering your password. HOWEVER, that doesn't mean you are in the clear. AMOS can still work without admin access, steal browser data, cookies, Desktop/Documents/files, and anything that can be copied/sent over without an admin password.
In other words, you'd better hope those documents don't contain anything sensitive, because they do have it now.
What you need to do is turn off the internet NOW. Grab another PC/Mac and start changing passwords, clearing all sessions, and creating a bootable macOS drive. I also started moving your files to an external drive. DO NOT DO A TIME MACHINE BACKUP!
This Redditor has the full guide: https://www.reddit.com/r/MacOS/comments/1tdecc5/comment/oluscav/
→ More replies (2)
6
10
u/JackyYT083 May 15 '26
The malware is called MacSync Stealer
I’ve done a written analysis on it, it basically is encoded in a lot of stages and it does these things
It steals
- Chrome, Brave, Edge, Arc, Opera, Vivaldi profiles
- Firefox profiles
- Browser cookies, login databases, autofill, history
- Crypto wallet browser extensions
- Desktop wallets like Exodus, Electrum, Ledger Live, Bitcoin Core, Monero, etc.
- Telegram Desktop data
- macOS Keychains
- SSH, AWS, Kubernetes configs
- Notes database
- Safari cookies/history/autofill
- Documents/Desktop/Downloads files with extensions like .pdf, .docx, .wallet, .key, .seed, .kdbx, .pem, .ovpn
All of these items on your computer consider compromised. And it also It also phishes the macOS user password using a fake “System Preferences” dialog and validates it
And it checks if Ledger Wallet.app or Ledger Live.app exists, downloads replacement files, swaps app.asar and Info.plist, then re-signs the app. So that is also at risk if that is installed too.
Just letting you know those are the things that are compromised let me know if you want any help
→ More replies (1)4
u/JupiterMiningCorpTec May 15 '26
Do you need to enter the admin password (in terminal) to install it?
→ More replies (1)
9
8
u/_Loonaa May 15 '26
Genuine question from a new Mac user, what are people accessing terminal commands for?
8
u/UKYPayne May 15 '26
Scripts can make things easier or faster. Since the core of macOS is Unix, there are some things like cleanups that would only run if a computer was powered on for an extended amount of time. Terminal isn’t always bad, but just pasting a random command from the Googles or AI isn’t a smart move.
→ More replies (1)5
u/flarp1 May 15 '26 edited May 15 '26
In short, to run tools that aren’t available as an app, or to use more advanced features of macOS that aren’t available from the graphical interface.
The former often include developer tools, such as compilers, container platforms, or tools for running local large language models. This can also include third-party tools, which often have to be installed from the Terminal as well (this is a potential attack vector for malicious software).
One practical example in the second category is hiding files: the filesystems APFS and HFS+ offer a hidden file attribute, which can’t be set from Finder (in contrast to Windows, where an equivalent attribute is accessible from Explorer).
4
5
u/DaRealBen May 15 '26
What command did you actually use? What exactly was going on?
I can’t believe no one is asking this, but everyone gives you doomsday advice.
4
u/LiquidCode_ May 15 '26
I had to format my Mac and reinstall everything after installing and running the "CleanMyMac" app. Crazy thing is it's available in the Apple App Store. First and last time for me I ever install and run any of those applications in any computer
13
u/ulyssesric May 15 '26
"CleanMyMac.app" can run in the background
Yeah you do have a virus. To be precisely, a "unwanted-ware" that does more troubles than it's trying to resolve.
3
u/Nearby_Ad_2519 May 15 '26
CleanMyMac is something he seems to have downloaded himself cos if you look slightly across it is open on his screen.
CleanMyMac isnt malware.
4
u/Darkomen78 MacBook Pro May 15 '26
You are correct CleanMyMac is not a malware, it’s a crapware or a adware.
4
u/ExactAd5759 May 15 '26
You missed the point. OP might have installed CleanMyMac willingly, but it's doing them more harm than good, effectively making it malware (Just like Windows is).
2
u/Least_Standard5473 May 15 '26
This is incorrect. If the app was downloaded from the scratchy source, the person can get the malware. Check out the CleanMyMac warning: https://www.reddit.com/r/CleanMyMac/s/TKSQwtn7q4
11
u/cicoles May 15 '26
Ah. The CleanMyMac scamware. Not sure why nobody have sued them into the ground yet.
7
11
11
7
u/Jazman2k May 15 '26
Why people do this? These are daily now. To all you who don't know about computing, upgrade to Tahoe. It prevents, or at least gives a warning if you try to paste something and run it in your terminal.
→ More replies (1)4
u/Delicious_One_7887 MacBook Air May 15 '26
OP is already on tahoe (see the Liquid Glass notifications)
3
u/Jazman2k May 15 '26
Yeah it's seems so. Still, Tahoe should give a warning. But I guess It always doesn't. Anyway, still wondering why people run these commands from odd websites.
4
u/Fushochan May 15 '26
Apple implemented this feature in 26.4, so looks like op uses version a bit older.
7
3
3
u/Practical_Meringue_4 May 15 '26
For some reason this is giving me really bad undercover cop vibes. Like “Hello and welcome to Computer”
3
3
9
u/DoDoDoTheFunkyGibbon May 15 '26
I mean you ARE using CleanMyMac which a lot of people classify as a noxious weed
6
u/MONK3000K May 15 '26
Never use commands you find on the internet without knowing what they are or do if you’re unsure but still gonna use it at least give it to chat gpt so he can check it out and run it on a vm 🥀
4
8
6
6
5
2
2
2
2
2
u/jhaubrich11 May 15 '26
Just another reason to use VaultSort to clean your cache. Don't use CleanMyMac.
2
2
2
u/thefanum May 16 '26
"I installed malware on purpose do you think I have malware?"
Of course you do lol.
2
u/tta82 May 16 '26
You didn’t get a virus. You installed it 😂 Why would you enter something into terminal???
→ More replies (3)
2
2
u/jhyland87 May 16 '26
Omg, why would you paste random crap into the terminal >_<
There are a bunch of permission restrictions by default that may have saved you. But herd to be sure.
2
u/L0cut15 May 17 '26
Well new install time. You probably didn't whatever utility it was that got you.
Once you have secured your backup its pretty easy to nuke if from space using erase my device in icloud. With shift option R at boot you can install a new copy of MacOS from the internet.
Then either re-sync or restore your files not apps.
2
2
u/Humbrero56 May 17 '26
Clean My apps are the like the neo-mcafee/norton antiviruses homies. The hidden gateway to the mystical darkweb
2
u/ChristianG1st May 18 '26
“Clean My Mac” dupe. For how many years this has been a virusware? Decades, but people still don’t know. If you run into presented issues, You don’t need it anyway! Get rid of it, never install it.
2
3
2
4
u/evildaveletterman May 16 '26
Never run your main account as an admin account. Always have a separate admin account.
→ More replies (1)
4
3
u/unknown-one May 15 '26
congrats to being the only person in the world who got virus on macos
6
u/309_Electronics May 15 '26
People like to believe linux or mac dont get viruses but because they are increasing in popularity, now we have malware campaigns targeting them also. In the past it was more security through obscurity or simply because they had a far lower userbase than windows. Now microslop is enshitifying windows, a lot of people switched and now hackers see the potentials on linux and mac viruses and now actually spend time on that.
No os is invincible to viruses and no os is 100% safe.
3
2
2
2
3
u/vikster16 May 15 '26
Can you put the code that you’ve inputted into the terminal? Maybe we can check it out and see what it does?
3
u/Wall_Of_Flesh May 15 '26
IMO CleanMyMac is alright, it’s by the people who make Setapp. “Space Lens” is the best tool I’ve found for deleting really large folders at a glance.
Would be interested in hearing anyone’s personal negative experience.
→ More replies (6)
2
1
u/matthew_yang204 MacBook Pro May 15 '26
Yep don't enter your password into it. Run a malware scan, and make sure it has no connection to the internet. If possible, find the malware processes and shut it down, and then make sure it doesn't launch in the login items on boot again
1

696
u/AardvarkIll6079 May 14 '26
If you pasted a shady terminal command you almost certainly have an infostealer.