maple30.com: a Mac malware host tagged Amos and ClickFix, and what to do if you ran a command from it

maple30.com is a website that URLhaus lists for Mac malware downloads tagged Amos and ClickFix, and it shares an identical file address with another listed host, quillchant14.com. If you pasted a command from it into Terminal on your Mac, change your passwords from another device, move any crypto, and then erase and reinstall macOS.

Facts checked October 10, 2026. Removal steps checked against Apple's current documentation and the security vendors' reports. We have not run the malware on a Mac.

Automatic

Get a free scan and check if your Mac is infected.

Fortect for Mac scans for malware and unwanted programs, and its free scan shows what it finds before you decide anything.

If a script or program from maple30.com, or a command pasted from its page into Terminal keeps coming back after uninstalling, a scan can find what reinstalls it.

Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free.

Do it yourself · free Remove maple30.com (Amos, ClickFix, macOS) yourself 7 steps, about 21 minutes, no software needed.

Start the steps
Table of four URLhaus entries for maple30.com added on 26 September 2026: a Mach-O file tagged Amos, ClickFix and macOS that was online, and three offline shell script files
The four URLhaus entries for maple30.com that we read on 10 October 2026, with the long path shortened and the domain defanged. Our own browser test got only a Cloudflare error page, so this table is the main evidence.

Maple30.com (Amos, ClickFix, macOS): summary

TypeA malware download address for Macs: URLhaus lists a Mach-O program tagged Amos and three shell scripts
RiskHigh if you pasted its command or opened its files: passwords, sessions, crypto and developer keys may have been taken
SymptomsOften none. A pasted line in Terminal, an unexpected password prompt or an unknown Login Item are the signs
How to get rid of itDisconnect, change passwords from another device, move crypto, back up documents, then erase the Mac and reinstall macOS
Our check (10 October 2026)One visit: Cloudflare error 520, no page. A broken or quiet site clears nothing; the rating comes from URLhaus
Running since / first seenDomain registered 14 August 2026; first malware URLs reported 26 September 2026
Removal

Scan the Mac with security software to find the malware and anything installed with it. Fortect for Mac scans for malware and unwanted programs.

Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free.
Show 9 more facts
PlatformmacOS, by the tags macOS, Mach-O and ua-curl
Detection namesNo Microsoft detection name is known for the files on this server, because we did not open them and we did not check them against Microsoft's list. The URLhaus tags are Amos, ClickFix, Mach-O, macOS and ua-curl
NameMaple30.com
Domain registered14 August 2026
Evidence4 write-ups by security sites; details still limited
First seen26 September 2026
DistributionTypically fake installers, cracked programs, e-mail attachments, fake "verify you are human" pages and ads for popular apps
DamageInstalls other malware, often several programs at once
Facts checked10 October 2026

Facts checked on 10 October 2026 against our copy of the URLhaus data for maple30.com, RDAP, one browser visit of our own, Palo Alto Networks Unit 42, Malwarebytes and Apple Platform Security. We did not download the files and we infected no Mac; the removal steps and menu paths were not tried on a live infection.

What maple30.com is, and what the record shows

maple30.com is a web address, not something installed on your Mac. The abuse.ch project URLhaus lists it as a place where Mac malware was served, and its main entry carries the tag Amos, the name of a family of Mac information stealers. We found no public write-up of this domain, so the page rests on the URLhaus record, our own visit and what Palo Alto Networks, Malwarebytes and Apple have published about the same kind of attack.

  1. 1

    The main entry

    A Mach-O program under a path that starts with /f/ was added on 26 September 2026 at 07:45 UTC by the reporter c4ffeine. Its tags are Amos, ClickFix, Mach-O, macOS and ua-curl. It was still marked online when we read the database on 10 October 2026.

  2. 2

    The three scripts

    Under /curl/ the reporter nikorasu added setup.sh, setup.command and update.sh, each with a random folder name and only the tag malware. All three were offline. A file ending in .command opens in Terminal when you double-click it on a Mac, so that name suggests a script meant to be started by a person.

  3. 3

    What the tags tell you

    ua-curl means the file was fetched by the curl command line tool, which is how a pasted command downloads things. Mach-O is the Mac program format. ClickFix is the reporter's label for a trick where a web page gets you to run the command yourself.

  4. 4

    What we could not confirm

    We downloaded nothing and never saw the page that tells visitors what to paste. We do not know the lure, what each script does, or whether the four files belong to one chain. Amos and ClickFix are the reporters' labels.

Kind of threat
A malware download address for Macs, with a Mach-O program tagged Amos
Delivery trick
ClickFix: a page asks you to copy a command and paste it into Terminal
Domain registered
14 August 2026, expires 14 August 2027, registrar Dominet (HK) Limited (RDAP, read 10 October 2026)
URLhaus entries
4 file addresses, all added on 26 September 2026; 1 online and 3 offline when we read them
Platform
macOS, by the macOS, Mach-O and ua-curl tags and the .command file

What maple30.com (Amos, ClickFix, macOS) does on an infected Mac

The same file address on a second domain

Searching our copy of the URLhaus feed for the main file's path turns up one other host: quillchant14.com. The two entries have an identical path and identical tags, which is a sign that one operator runs both.

Two cards for maple30.com and quillchant14.com showing the same file path and the same Amos, ClickFix, Mach-O, macOS and ua-curl tags, reported by the same person on 26 September 2026
maple30.com and quillchant14.com in URLhaus. The long random part of the path is the same on both. Source: our copy of the feed, read 10 October 2026.
Sources: URLhaus and RDAP, read 10 October 2026.
maple30.comquillchant14.com
Domain registered14 August 202622 September 2026
RegistrarDominet (HK) LimitedDominet (HK) Limited
Main file reported26 September 2026, 07:45 UTC26 September 2026, 06:23 UTC
Main file tagsAmos, ClickFix, Mach-O, macOS, ua-curlAmos, ClickFix, Mach-O, macOS, ua-curl
Our test on 10 October 2026Cloudflare error 520Cloudflare error 520

What this means: a block on one name does not stop the other, and a list of bad domains goes out of date fast. What we cannot say is who runs them, or how many more names serve the same file. Our own guide to quillchant14.com covers that host.

Our visit on 10 October 2026, and why it settles nothing

We opened https://maple30.com/ once, from Lithuania, in an automated Chromium browser set to English. Cloudflare answered with error 520 and no page loaded.

Our site test, 10 October 2026

  • Only an error pageThe title was 520: Web server is returning an unknown error. Cloudflare explains this as an unknown connection problem between its network and the origin server. Cloudflare itself worked, so the domain sits behind it and the server behind it gave us nothing usable.
  • Why that is not a clean resultThe server may be down, closed by its operators, or set to refuse our kind of visitor. One visit cannot tell. Malware hosts often answer differently by country, device and tool, and curl can fetch a file that a browser never gets.
  • Notification request, pop-ups, redirects, ad networksNone seen, because no page loaded on this one visit.
  • URLhaus listingFour malware addresses on the domain. The Mach-O file tagged Amos was online when we read the database.
  • Downloads and page contentWe did not download the files and did not reach a page that shows a command, so we cannot say what the scripts do.

Dangerous: treat it as a malware site The visit proves nothing either way. The rating comes from the URLhaus reports and the shared file with quillchant14.com. Do not open files from this site and do not run any command it gives you.

Timeline: from registration to our visit

The domain is about eight weeks old at our test. The gap between registration and the first report is six weeks, which is longer than for its twin.

  1. 14 August 2026

    The domain is registered

    RDAP shows maple30.com registered through Dominet (HK) Limited, valid until 14 August 2027. The name says nothing about a business, and we found none behind it.

  2. 26 September 2026, 06:23 UTC

    Three scripts are reported

    The reporter nikorasu adds update.sh, setup.sh and setup.command, all within about one second and all tagged malware.

  3. 26 September 2026, 07:45 UTC

    The Mach-O program is reported

    The reporter c4ffeine adds the file under /f/ with the tags Amos, ClickFix, Mach-O, macOS and ua-curl. It is the same path that was reported on quillchant14.com about 80 minutes earlier.

  4. 10 October 2026

    Our visit gets error 520

    At about 08:57 UTC our single visit returns the Cloudflare error. The main file is still marked online in the database; the scripts are offline.

How a ClickFix command infects a Mac

ClickFix needs no security hole. You run the command, so Mac checks that guard downloaded apps rarely get involved. We did not see maple30.com's page; this is how Palo Alto Networks and Malwarebytes describe the attack.

  1. 1

    A page gives you a reason to open Terminal

    Unit 42 describes a page offering a macOS toolkit with quick setup instructions. Malwarebytes lists cracked software and fake guides for freeing disk space among the lures.

  2. 2

    A line is copied for you

    In the cases described, the line begins with curl and passes what it downloads to a shell, so the whole attack is one line.

  3. 3

    A script fetches a second script, then a program

    Unit 42's example fetched a zsh script that held a compressed, encoded block. That unpacked into a second script, which downloaded a Mach-O program into /tmp and ran it.

  4. 4

    The program asks for your password

    The installer in that case asked for the Mac password and the infection went on because the account was an administrator. Terminal then asked to control Finder and Notes and to reach Desktop and Documents.

  5. 5

    Data goes out in stages

    The collected files were zipped in /tmp and posted to the attacker in stages named boot, credentials, browsers, wallets, messengers and local_data.

Apple says Gatekeeper is designed to help ensure that only trusted software runs on a Mac, and that it asks for approval before downloaded software opens for the first time. A line you paste yourself starts work through Terminal, so you should not count on that prompt as your protection.

The four files, one by one

Names are weak evidence. The third column is our reading of each name, not a finding.

Source: the URLhaus database, read 10 October 2026.
File on maple30.comWhat URLhaus saysWhat it may be (our reading)
/f/ path ending sfjwmrjyOnline, tagged Amos, ClickFix, Mach-O, macOS, ua-curl, 26 September 2026, c4ffeineA Mac program with no ending: the stealer itself, as labelled by the reporter
setup.sh under /curl/Offline, tagged malware, 26 September 2026, nikorasuA shell script posing as an installer. Not confirmed
setup.command under /curl/Offline, tagged malware, 26 September 2026, nikorasuA script that Terminal opens when double-clicked. Not confirmed
update.sh under /curl/Offline, tagged malware, 26 September 2026, nikorasuA script with a routine name. Not confirmed

What maple30.com (Amos, ClickFix, macOS) can steal or download

What an Amos infection can take

We do not know that the file here is Amos. Below is what Unit 42 reports from an Amos infection that began with a pasted command, as a picture of what may be at stake.

Data Unit 42 saw gathered on one infected Mac

  • Crypto wallet data (Binance and TonKeeper)
  • Cloud and developer logins (AWS, Docker, Google Cloud, FileZilla)
  • The zsh command history
  • Telegram data
  • System details and the user name
  • Browser and messenger data
Source: Palo Alto Networks Unit 42, published 16 September 2026, read 10 October 2026.
Part of the attackWhat it does to youSource
Password promptGains administrator rights if you type your Mac passwordUnit 42
Access requestsAsks Terminal to control Finder and Notes and to read Desktop and DocumentsUnit 42
CollectionPacks the files into an archive in /tmp, then uploads them in stagesUnit 42
PersistenceIn that case: hidden folders under Library/Application Support with names starting .com.apple, and scripts that start at login. We do not know whether this host does the sameUnit 42

Who is at risk, and how much

Seeing the name in a log or a warning is harmless. The risks below are for a Mac where the command ran or a file from the site was opened.

  • High

    Stolen logins and sessions

    Browser data lets someone sign in as you. A new password may not end a session that was already copied.

  • High

    Crypto

    Wallet files and apps are a target, and a transfer cannot be undone. Move funds from a clean device first.

  • High

    Developer keys

    Cloud keys and shell history can reveal servers and tokens. Revoke them and make new ones.

  • Medium

    Login items that start again

    If the malware set up files that run at login, the Mac contacts the attacker again after each restart.

  • Medium

    A work Mac

    Tell your IT team at once so they can block the accounts that were on the Mac.

  • Low

    Only saw the name

    No risk from that alone.

Signs on the Mac, and why many people see none

A stealer finishes in minutes and can leave no sign. Look for these anyway.

Sources: Unit 42 for the prompts; the rest follows from how the chain works.
SignWhat it means
A pasted line in TerminalA long line with curl, a web address, base64, zsh or bash is the command
A password window right after you pressed ReturnThis is how the installer in Unit 42's case gained rights
Terminal asking for access to Finder, Notes, Desktop or DocumentsUnit 42 saw this after the infection began
A new item in Login Items & ExtensionsPossible persistence
Account alerts or password-reset emailsOur reading of stolen sessions, not a quote
Nothing at allCommon, because stealers are built to stay quiet

How to check the Mac for maple30.com (Amos, ClickFix, macOS)

How a visitor might get there

No source says how people reach maple30.com. These are the routes published for Mac ClickFix campaigns in general.

  1. 1

    Free or cracked software

    A search for a pirated Mac app ends on a page that says you must run a line in Terminal to install it.

  2. 2

    A fix or a tool guide

    Pages that pose as help to free disk space or install a toolkit.

  3. 3

    A fake human check

    A page that wants you to copy something and paste it into a window to prove you are real.

  4. 4

    A hacked site or a paid ad

    Either can send you to such a page. We have no source linking this to maple30.com.

Look over the Mac before you change anything

The question that decides everything: did you paste a command from a website into Terminal, or open a file from maple30.com? If yes, follow the plan on this page, since a clean look does not clear a Mac. If you are not sure, do the read-only checks below. Meanwhile turn Wi-Fi off in the menu bar and stop using the Mac for banking, mail, work or crypto.

Table of five places to check on a Mac after a pasted command: Terminal, Login Items, LaunchAgents folders, Privacy and Security, and Activity Monitor, with what to look for in each
Five read-only checks on a Mac after a pasted command. A clean result lowers the doubt and does not clear the Mac.
  1. 1

    Terminal

    Open Terminal from Applications > Utilities. Read the lines on screen and scroll up. Write down any line that names maple30.com or has curl, base64, zsh or bash with a web address. Do not run it.

  2. 2

    Login Items

    Open System Settings > General > Login Items & Extensions (macOS Ventura, Sonoma, Sequoia and newer). Read both lists and note anything you did not add.

  3. 3

    LaunchAgents

    In Finder choose Go > Go to Folder and open ~/Library/LaunchAgents, /Library/LaunchAgents and /Library/LaunchDaemons. Note files dated after you pasted the command.

  4. 4

    Privacy & Security

    Open System Settings > Privacy & Security and look at Full Disk Access, Automation and Files and Folders. Terminal or an unknown app that you never allowed deserves a note.

  5. 5

    Activity Monitor

    Open Activity Monitor from Utilities and open the Network tab. A process you do not know that keeps sending data is worth a note. Do not quit it yet.

  6. 6

    What a clean result means

    It lowers the doubt. It does not clear the Mac, because the stealer may have run, sent everything and deleted itself.

How to remove maple30.com (Amos, ClickFix, macOS)

How to remove maple30.com from a Mac

Start with the passwords and crypto, from another device: a stealer copies them in seconds.

Then clean the Mac, or erase it.

  1. Step 1: Change passwords from another device first

    If you pasted a command into Terminal or opened a downloaded file from maple30.com, assume the passwords saved in the browsers and in Keychain on this Mac are known to the attacker.

    From a phone or a clean computer, change the e-mail password first, then banking, shopping, social and work accounts, and sign out of all other sessions on each one.

    Move any cryptocurrency to a new wallet created on a clean device, because a seed phrase that was stored on this Mac is compromised. Do this before cleaning the Mac: cleaning does not undo the theft.

    Full procedure with screenshots: Turn on two-step verification / secure a hacked account

  2. Step 2: Quit what is running that you do not recognize

    Open Activity Monitor (in Applications > Utilities, or search for it with Command + Space).

    In the CPU or Network tab, look for a process you did not install or whose name is random, select it, click the stop button (the octagon with an X) and choose Quit or Force Quit.

    Note the name first: you will look for the same name in the next steps. Malware that comes back after a restart is handled in the next two steps.

  3. Step 3: Remove unknown login items and background items

    Open System Settings > General > Login Items & Extensions. Under Open at Login and Allow in the Background, switch off or remove anything you do not recognize, especially items whose developer is shown as an unknown name or that appeared on the day you ran the command.

    Then open Finder, choose Go > Go to Folder and check ~/Library/LaunchAgents, /Library/LaunchAgents and /Library/LaunchDaemons for property list (.plist) files you did not add. Drag suspicious ones to the Bin, then restart the Mac.

  4. Step 4: Delete apps and downloads you did not intend to install

    Open the Applications folder and your Downloads folder. Drag any app you did not install, and any disk image (.dmg), installer (.pkg) or archive (.zip) that came from maple30.com or a site you do not trust, to the Bin, then empty the Bin.

    Also check ~/Library/Application Support for a folder with the same name as the app you removed.

  5. Step 5: Check the browsers for extensions and changed settings

    In Safari open Settings > Extensions and General (homepage). In Chrome open chrome://extensions, in Firefox about:addons.

    Remove any extension you did not add, and reset the homepage and search engine if they changed. Browsers hold saved passwords and cookies, which is why the password step comes first.

  6. Step 6: If it was an infostealer, erase and reinstall macOS

    Stealers copy data and often leave persistence you cannot be sure you found.

    The only complete fix is to back up your personal files only (documents, photos, not apps or settings), then open System Settings > General > Transfer or Reset > Erase All Content and Settings, or use macOS Recovery to erase the disk and reinstall macOS, as Apple describes in its support articles.

    Restore only your files afterwards, and install apps again from their official sources.

  7. Step 7: Report it and watch your accounts

    Report the site and the command to the authorities in your country, and tell your bank if any card was saved in a browser or in Keychain.

    Over the next weeks watch your e-mail, bank and exchange accounts for sign-ins and transfers you did not make. Keep the notes you made, such as the process names and the file dates, in case a bank or the police ask for them.

    Full procedure with screenshots: Report a cyber attack or scam to the authorities

Updates and a second opinion

The Mac has no scan that proves it is clean. Updates and a scanner help for later, but they do not undo what was already sent.

  1. 1

    Install updates

    Open System Settings > General > Software Update and install what is offered. Malwarebytes reports a Terminal warning on pasted commands in macOS Tahoe 26.4, which Apple has not documented.

  2. 2

    Review file access

    In Privacy & Security remove Terminal or any unknown app that has Full Disk Access or Automation rights you did not give.

  3. 3

    Use a scanner as a second opinion

    A Mac scanner may find known Amos files and login entries. A quiet result does not clear the Mac.

If your device is not a Mac

The tags and the .command file point at macOS.

DeviceWhat we knowWhat to do
Windows PCA Mach-O program does not run on Windows. ClickFix also exists for PCs, with the Run box and PowerShellIf you pasted a command into Run or PowerShell, use our Windows guides
iPhone or iPadNo place to paste a commandChange passwords if you typed any on the page
AndroidNo source mentions itChange passwords if you typed any on the page

After removal: passwords, accounts and prevention

Recovery: accounts first, then the Mac

Follow this order: another device, then crypto, then the Mac.

  1. 1

    Passwords from a clean device

    On a phone or another computer, change your email password first, then banking, work and social accounts. Change your Apple Account password at account.apple.com.

  2. 2

    Sessions and keys

    Use each account's option to sign out everywhere. Revoke API tokens, SSH keys and cloud keys that were on the Mac.

  3. 3

    Keychain

    Treat every password in the login keychain as known to the attacker and change the important ones.

  4. 4

    Crypto

    If a recovery phrase was on the Mac, make a new wallet on a clean device and move the funds.

  5. 5

    Two-factor sign-in

    Turn it on with an authenticator app or a security key wherever the account offers it.

  6. 6

    Erase and reinstall

    Copy documents and photos only. Then use System Settings > General > Transfer or Reset > Erase All Content and Settings on a Mac with Apple silicon or a T2 chip, or erase the disk in macOS Recovery and reinstall. Set up as new.

  7. 7

    Monitor

    For several weeks watch your bank, mail and crypto, and tell your bank at once about anything you did not do.

How to avoid the next one

One rule covers it: a website never needs you to paste a line into Terminal.

Do

  • Close any page that asks you to paste a command into Terminal.
  • Keep macOS and your browser current.
  • Get Mac apps from the App Store or the developer's own site.
  • Keep a backup on a disk that is unplugged.
  • Use an authenticator app for important accounts.

Don't

  • Do not paste a command to pass a check or free disk space.
  • Do not click Paste Anyway on a warning about a line you did not write.
  • Do not type your Mac password into a window that appeared after a pasted line.
  • Do not run cracked software installers.
  • Do not take a quiet scan as proof you are safe.

Questions about maple30.com (Amos, ClickFix, macOS)

What is maple30.com?

It is a website that URLhaus lists for serving Mac malware, not a program on your computer. Four file addresses on it were added on 26 September 2026, one of them a Mach-O program tagged Amos and ClickFix.

The domain was registered on 14 August 2026. It shares an identical file address with quillchant14.com, which points to one operator behind both. On 10 October 2026 our visit got a Cloudflare error, so we cannot say what the site shows today.

If you only saw the name in a warning, you are not infected by that. If you ran a command or opened a file from it, use the steps on this page.

Is maple30.com safe to open?

Do not treat it as safe. Opening a page is not the same as running its command, but a malware host can show a convincing fake check and push you to paste a line into Terminal. Our own visit only got a Cloudflare error, which clears nothing, because malware sites often answer differently by country, device or tool.

Do not open files from it and do not paste anything it gives you. If you already visited and did nothing more, close the tab, clear the site data in your browser and carry on. The risk starts when a command is run.

What does Amos do to a Mac?

Amos is a family of Mac information stealers. Palo Alto Networks describes one infection that asked for the Mac password, then collected crypto wallet data, cloud and developer logins, shell history and Telegram data into an archive and uploaded it in stages.

We do not know that the file on maple30.com is Amos, since the tag comes from a reporter and we did not open the file. Treat it as a strong warning. Families like this change often, so details from one report may not match another.

What is ClickFix, and why does Terminal matter?

ClickFix makes you infect yourself. A page shows a fake check, a fix or a setup guide and tells you to copy a line and paste it into Terminal.

The line usually starts with curl and downloads a script that fetches the real malware. No security hole is used. Because you start the command, the first-open check that Apple applies to downloaded apps does not work as a barrier.

Palo Alto Networks notes that a fake toolkit setup page is not a strict ClickFix, but it uses the same paste step. The safe rule is simple: never paste a command from a web page.

I ran the command from this site. What now?

Turn off Wi-Fi and stop using the Mac for anything important. On a phone or another computer change your email password first, then banking, work and social accounts, and sign out of every session. Move crypto to a new wallet made on a clean device.

Revoke any cloud or developer keys that were on the Mac. Only then copy documents and photos to a drive and erase the Mac and reinstall macOS. Accounts come first because the data may already be gone, so they are at risk before the Mac is.

Why are maple30.com and quillchant14.com linked?

In our copy of the URLhaus feed the main Mach-O file has the same long path and the same tags on both domains, and the same reporter filed both entries on 26 September 2026, about 80 minutes apart. Both domains use the registrar Dominet (HK) Limited, and both answered our test with a Cloudflare error.

That fits one operator running two names for one file. It does not prove who the operator is, how many other names serve the file, or that the two sites look alike. Blocking one domain does not stop the other.

Will Gatekeeper or the Terminal warning protect me?

Not reliably. Apple says Gatekeeper is designed to help ensure that only trusted software runs on a Mac, and that it asks for approval before downloaded software opens for the first time. A command you paste starts the work from Terminal, so that prompt is not the barrier.

Malwarebytes reports that macOS Tahoe 26.4 shows a Possible malware, Paste blocked warning for some pasted commands, with a Paste Anyway choice. Apple has not documented it and it does not flag everything. Use both as a help, and keep the rule of never pasting a command from a page.

Can I just delete the files and be done?

No. Deleting a file removes the file, not the damage. A stealer takes your data in minutes and may remove itself, so the real risk is what was already sent:

  • saved passwords
  • sessions
  • wallet data
  • keys

Some Amos infections also leave hidden folders and login items that start the program again. If you ran the command, change your passwords from another device, move crypto, and erase the Mac and reinstall macOS. If you only opened the page and pasted nothing, there is nothing to delete.

How do I know whether I ran the command?

Think back to whether any page told you to open Terminal and paste something. If so, open Terminal and read the lines on screen. A long line with curl, a web address, base64, zsh or bash is the command.

Also ask yourself whether a password window appeared right after you pressed Return, and whether Terminal asked to control Finder or Notes or to reach Desktop and Documents. Check System Settings, General, Login Items & Extensions for items you did not add. If you are unsure, assume you did, because the cost of checking is small.

Will Fortect remove maple30.com?

Fortect for Mac scans for malware and unwanted programs, and its free scan shows what it finds on your Mac before you decide anything.

For maple30.com, follow the plan on this page as well: removing a launch item or an app is done in macOS itself, and a scanner cannot undo what was typed or entered on the infected Mac, such as saved passwords that were copied.

Change your passwords from another device first, and if the page tells you to erase the Mac, a scan is not a substitute. The free scan costs nothing and the full-featured product needs a license.

Sources

More removal guides

Remove swatting.wiki: a Mirai botnet download address for routers and cameras, and what to do if a device of yours may be infected

swatting.wiki is a web address that URLhaus lists for 14 malware downloads, every one tagged mirai, a botnet that takes over routers, cameras and other small network devices. The name no longer resolves when we look...TRHigh riskUgnius Kiguolis ·

Remove quillchant14.com: a Mac ClickFix site that serves the Amos stealer, and what to do if you pasted its command

quillchant14.com is a website that URLhaus lists for Mac malware downloads tagged ClickFix and Amos, and it answered our test with a Cloudflare error instead of a page. If you pasted a command from it into Terminal...TRHigh riskUgnius Kiguolis ·

Remove power.belyxhost.in: a Mirai botnet download address for routers and cameras, and what to do if a device of yours may be infected

power.belyxhost.in is a web address that URLhaus lists for 15 malware downloads, 14 of them tagged mirai, a botnet that takes over routers, cameras and other small network devices. The name no longer resolves when we...TRHigh riskUgnius Kiguolis ·

Remove rabbids.cc: a Windows infostealer download site that uses DLL sideloading, and what to do if you ran a file from it

rabbids.cc is a web address that URLhaus lists for 5 malware downloads, tagged infostealer, stealer and dll-sideloading, among them a zip archive and a file named 7za.exe that were still online when we checked. If...TRHigh riskUgnius Kiguolis ·

Questions and experiences: maple30.com (Amos, ClickFix, macOS)

Still seeing it, or found something we did not cover? Ask here: members and our editors answer. Reading is open; writing needs a free account.

0 comments

…

5,449 members already hereReading, writing, commenting and voting. 0 verified · 174 joined this year