maple30.com: a Mac malware host tagged Amos and ClickFix, and what to do if you ran a command from it
maple30.com is a website that URLhaus lists for Mac malware downloads tagged Amos and ClickFix, and it shares an identical file address with another listed host, quillchant14.com. If you pasted a command from it into Terminal on your Mac, change your passwords from another device, move any crypto, and then erase and reinstall macOS.
Facts checked October 10, 2026. Removal steps checked against Apple's current documentation and the security vendors' reports. We have not run the malware on a Mac.
Automatic
Get a free scan and check if your Mac is infected.
Fortect for Mac scans for malware and unwanted programs, and its free scan shows what it finds before you decide anything.
If a script or program from maple30.com, or a command pasted from its page into Terminal keeps coming back after uninstalling, a scan can find what reinstalls it.
Do it yourself · free Remove maple30.com (Amos, ClickFix, macOS) yourself 7 steps, about 21 minutes, no software needed.
Start the steps
Maple30.com (Amos, ClickFix, macOS): summary
| Type | A malware download address for Macs: URLhaus lists a Mach-O program tagged Amos and three shell scripts |
|---|---|
| Risk | High if you pasted its command or opened its files: passwords, sessions, crypto and developer keys may have been taken |
| Symptoms | Often none. A pasted line in Terminal, an unexpected password prompt or an unknown Login Item are the signs |
| How to get rid of it | Disconnect, change passwords from another device, move crypto, back up documents, then erase the Mac and reinstall macOS |
| Our check (10 October 2026) | One visit: Cloudflare error 520, no page. A broken or quiet site clears nothing; the rating comes from URLhaus |
| Running since / first seen | Domain registered 14 August 2026; first malware URLs reported 26 September 2026 |
| Removal | Scan the Mac with security software to find the malware and anything installed with it. Fortect for Mac scans for malware and unwanted programs. Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free. |
Show 9 more facts
| Platform | macOS, by the tags macOS, Mach-O and ua-curl |
|---|---|
| Detection names | No Microsoft detection name is known for the files on this server, because we did not open them and we did not check them against Microsoft's list. The URLhaus tags are Amos, ClickFix, Mach-O, macOS and ua-curl |
| Name | Maple30.com |
| Domain registered | 14 August 2026 |
| Evidence | 4 write-ups by security sites; details still limited |
| First seen | 26 September 2026 |
| Distribution | Typically fake installers, cracked programs, e-mail attachments, fake "verify you are human" pages and ads for popular apps |
| Damage | Installs other malware, often several programs at once |
| Facts checked | 10 October 2026 |
Facts checked on 10 October 2026 against our copy of the URLhaus data for maple30.com, RDAP, one browser visit of our own, Palo Alto Networks Unit 42, Malwarebytes and Apple Platform Security. We did not download the files and we infected no Mac; the removal steps and menu paths were not tried on a live infection.
What maple30.com is, and what the record shows
maple30.com is a web address, not something installed on your Mac. The abuse.ch project URLhaus lists it as a place where Mac malware was served, and its main entry carries the tag Amos, the name of a family of Mac information stealers. We found no public write-up of this domain, so the page rests on the URLhaus record, our own visit and what Palo Alto Networks, Malwarebytes and Apple have published about the same kind of attack.
- 1
The main entry
A Mach-O program under a path that starts with /f/ was added on 26 September 2026 at 07:45 UTC by the reporter c4ffeine. Its tags are Amos, ClickFix, Mach-O, macOS and ua-curl. It was still marked online when we read the database on 10 October 2026.
- 2
The three scripts
Under /curl/ the reporter nikorasu added setup.sh, setup.command and update.sh, each with a random folder name and only the tag malware. All three were offline. A file ending in .command opens in Terminal when you double-click it on a Mac, so that name suggests a script meant to be started by a person.
- 3
What the tags tell you
ua-curl means the file was fetched by the curl command line tool, which is how a pasted command downloads things. Mach-O is the Mac program format. ClickFix is the reporter's label for a trick where a web page gets you to run the command yourself.
- 4
What we could not confirm
We downloaded nothing and never saw the page that tells visitors what to paste. We do not know the lure, what each script does, or whether the four files belong to one chain. Amos and ClickFix are the reporters' labels.
- Kind of threat
- A malware download address for Macs, with a Mach-O program tagged Amos
- Delivery trick
- ClickFix: a page asks you to copy a command and paste it into Terminal
- Domain registered
- 14 August 2026, expires 14 August 2027, registrar Dominet (HK) Limited (RDAP, read 10 October 2026)
- URLhaus entries
- 4 file addresses, all added on 26 September 2026; 1 online and 3 offline when we read them
- Platform
- macOS, by the macOS, Mach-O and ua-curl tags and the .command file
What maple30.com (Amos, ClickFix, macOS) does on an infected Mac
The same file address on a second domain
Searching our copy of the URLhaus feed for the main file's path turns up one other host: quillchant14.com. The two entries have an identical path and identical tags, which is a sign that one operator runs both.

| maple30.com | quillchant14.com | |
|---|---|---|
| Domain registered | 14 August 2026 | 22 September 2026 |
| Registrar | Dominet (HK) Limited | Dominet (HK) Limited |
| Main file reported | 26 September 2026, 07:45 UTC | 26 September 2026, 06:23 UTC |
| Main file tags | Amos, ClickFix, Mach-O, macOS, ua-curl | Amos, ClickFix, Mach-O, macOS, ua-curl |
| Our test on 10 October 2026 | Cloudflare error 520 | Cloudflare error 520 |
What this means: a block on one name does not stop the other, and a list of bad domains goes out of date fast. What we cannot say is who runs them, or how many more names serve the same file. Our own guide to quillchant14.com covers that host.
Our visit on 10 October 2026, and why it settles nothing
We opened https://maple30.com/ once, from Lithuania, in an automated Chromium browser set to English. Cloudflare answered with error 520 and no page loaded.
Our site test, 10 October 2026
- Only an error pageThe title was 520: Web server is returning an unknown error. Cloudflare explains this as an unknown connection problem between its network and the origin server. Cloudflare itself worked, so the domain sits behind it and the server behind it gave us nothing usable.
- Why that is not a clean resultThe server may be down, closed by its operators, or set to refuse our kind of visitor. One visit cannot tell. Malware hosts often answer differently by country, device and tool, and curl can fetch a file that a browser never gets.
- Notification request, pop-ups, redirects, ad networksNone seen, because no page loaded on this one visit.
- URLhaus listingFour malware addresses on the domain. The Mach-O file tagged Amos was online when we read the database.
- Downloads and page contentWe did not download the files and did not reach a page that shows a command, so we cannot say what the scripts do.
Dangerous: treat it as a malware site The visit proves nothing either way. The rating comes from the URLhaus reports and the shared file with quillchant14.com. Do not open files from this site and do not run any command it gives you.
Timeline: from registration to our visit
The domain is about eight weeks old at our test. The gap between registration and the first report is six weeks, which is longer than for its twin.
14 August 2026
The domain is registered
RDAP shows maple30.com registered through Dominet (HK) Limited, valid until 14 August 2027. The name says nothing about a business, and we found none behind it.
26 September 2026, 06:23 UTC
Three scripts are reported
The reporter nikorasu adds update.sh, setup.sh and setup.command, all within about one second and all tagged malware.
26 September 2026, 07:45 UTC
The Mach-O program is reported
The reporter c4ffeine adds the file under /f/ with the tags Amos, ClickFix, Mach-O, macOS and ua-curl. It is the same path that was reported on quillchant14.com about 80 minutes earlier.
10 October 2026
Our visit gets error 520
At about 08:57 UTC our single visit returns the Cloudflare error. The main file is still marked online in the database; the scripts are offline.
How a ClickFix command infects a Mac
ClickFix needs no security hole. You run the command, so Mac checks that guard downloaded apps rarely get involved. We did not see maple30.com's page; this is how Palo Alto Networks and Malwarebytes describe the attack.
- 1
A page gives you a reason to open Terminal
Unit 42 describes a page offering a macOS toolkit with quick setup instructions. Malwarebytes lists cracked software and fake guides for freeing disk space among the lures.
- 2
A line is copied for you
In the cases described, the line begins with curl and passes what it downloads to a shell, so the whole attack is one line.
- 3
A script fetches a second script, then a program
Unit 42's example fetched a zsh script that held a compressed, encoded block. That unpacked into a second script, which downloaded a Mach-O program into /tmp and ran it.
- 4
The program asks for your password
The installer in that case asked for the Mac password and the infection went on because the account was an administrator. Terminal then asked to control Finder and Notes and to reach Desktop and Documents.
- 5
Data goes out in stages
The collected files were zipped in /tmp and posted to the attacker in stages named boot, credentials, browsers, wallets, messengers and local_data.
Apple says Gatekeeper is designed to help ensure that only trusted software runs on a Mac, and that it asks for approval before downloaded software opens for the first time. A line you paste yourself starts work through Terminal, so you should not count on that prompt as your protection.
The four files, one by one
Names are weak evidence. The third column is our reading of each name, not a finding.
| File on maple30.com | What URLhaus says | What it may be (our reading) |
|---|---|---|
| /f/ path ending sfjwmrjy | Online, tagged Amos, ClickFix, Mach-O, macOS, ua-curl, 26 September 2026, c4ffeine | A Mac program with no ending: the stealer itself, as labelled by the reporter |
| setup.sh under /curl/ | Offline, tagged malware, 26 September 2026, nikorasu | A shell script posing as an installer. Not confirmed |
| setup.command under /curl/ | Offline, tagged malware, 26 September 2026, nikorasu | A script that Terminal opens when double-clicked. Not confirmed |
| update.sh under /curl/ | Offline, tagged malware, 26 September 2026, nikorasu | A script with a routine name. Not confirmed |
What maple30.com (Amos, ClickFix, macOS) can steal or download
What an Amos infection can take
We do not know that the file here is Amos. Below is what Unit 42 reports from an Amos infection that began with a pasted command, as a picture of what may be at stake.
Data Unit 42 saw gathered on one infected Mac
- Crypto wallet data (Binance and TonKeeper)
- Cloud and developer logins (AWS, Docker, Google Cloud, FileZilla)
- The zsh command history
- Telegram data
- System details and the user name
- Browser and messenger data
| Part of the attack | What it does to you | Source |
|---|---|---|
| Password prompt | Gains administrator rights if you type your Mac password | Unit 42 |
| Access requests | Asks Terminal to control Finder and Notes and to read Desktop and Documents | Unit 42 |
| Collection | Packs the files into an archive in /tmp, then uploads them in stages | Unit 42 |
| Persistence | In that case: hidden folders under Library/Application Support with names starting .com.apple, and scripts that start at login. We do not know whether this host does the same | Unit 42 |
Who is at risk, and how much
Seeing the name in a log or a warning is harmless. The risks below are for a Mac where the command ran or a file from the site was opened.
- High
Stolen logins and sessions
Browser data lets someone sign in as you. A new password may not end a session that was already copied.
- High
Crypto
Wallet files and apps are a target, and a transfer cannot be undone. Move funds from a clean device first.
- High
Developer keys
Cloud keys and shell history can reveal servers and tokens. Revoke them and make new ones.
- Medium
Login items that start again
If the malware set up files that run at login, the Mac contacts the attacker again after each restart.
- Medium
A work Mac
Tell your IT team at once so they can block the accounts that were on the Mac.
- Low
Only saw the name
No risk from that alone.
Signs on the Mac, and why many people see none
A stealer finishes in minutes and can leave no sign. Look for these anyway.
| Sign | What it means |
|---|---|
| A pasted line in Terminal | A long line with curl, a web address, base64, zsh or bash is the command |
| A password window right after you pressed Return | This is how the installer in Unit 42's case gained rights |
| Terminal asking for access to Finder, Notes, Desktop or Documents | Unit 42 saw this after the infection began |
| A new item in Login Items & Extensions | Possible persistence |
| Account alerts or password-reset emails | Our reading of stolen sessions, not a quote |
| Nothing at all | Common, because stealers are built to stay quiet |
How to check the Mac for maple30.com (Amos, ClickFix, macOS)
How a visitor might get there
No source says how people reach maple30.com. These are the routes published for Mac ClickFix campaigns in general.
- 1
Free or cracked software
A search for a pirated Mac app ends on a page that says you must run a line in Terminal to install it.
- 2
A fix or a tool guide
Pages that pose as help to free disk space or install a toolkit.
- 3
A fake human check
A page that wants you to copy something and paste it into a window to prove you are real.
- 4
A hacked site or a paid ad
Either can send you to such a page. We have no source linking this to maple30.com.
Look over the Mac before you change anything
The question that decides everything: did you paste a command from a website into Terminal, or open a file from maple30.com? If yes, follow the plan on this page, since a clean look does not clear a Mac. If you are not sure, do the read-only checks below. Meanwhile turn Wi-Fi off in the menu bar and stop using the Mac for banking, mail, work or crypto.

- 1
Terminal
Open Terminal from Applications > Utilities. Read the lines on screen and scroll up. Write down any line that names maple30.com or has curl, base64, zsh or bash with a web address. Do not run it.
- 2
Login Items
Open System Settings > General > Login Items & Extensions (macOS Ventura, Sonoma, Sequoia and newer). Read both lists and note anything you did not add.
- 3
LaunchAgents
In Finder choose Go > Go to Folder and open
~/Library/LaunchAgents,/Library/LaunchAgentsand/Library/LaunchDaemons. Note files dated after you pasted the command. - 4
Privacy & Security
Open System Settings > Privacy & Security and look at Full Disk Access, Automation and Files and Folders. Terminal or an unknown app that you never allowed deserves a note.
- 5
Activity Monitor
Open Activity Monitor from Utilities and open the Network tab. A process you do not know that keeps sending data is worth a note. Do not quit it yet.
- 6
What a clean result means
It lowers the doubt. It does not clear the Mac, because the stealer may have run, sent everything and deleted itself.
How to remove maple30.com (Amos, ClickFix, macOS)
How to remove maple30.com from a Mac
Start with the passwords and crypto, from another device: a stealer copies them in seconds.
Then clean the Mac, or erase it.
Step 1: Change passwords from another device first
If you pasted a command into Terminal or opened a downloaded file from maple30.com, assume the passwords saved in the browsers and in Keychain on this Mac are known to the attacker.
From a phone or a clean computer, change the e-mail password first, then banking, shopping, social and work accounts, and sign out of all other sessions on each one.
Move any cryptocurrency to a new wallet created on a clean device, because a seed phrase that was stored on this Mac is compromised. Do this before cleaning the Mac: cleaning does not undo the theft.
Full procedure with screenshots: Turn on two-step verification / secure a hacked account
Step 2: Quit what is running that you do not recognize
Open Activity Monitor (in Applications > Utilities, or search for it with Command + Space).
In the CPU or Network tab, look for a process you did not install or whose name is random, select it, click the stop button (the octagon with an X) and choose Quit or Force Quit.
Note the name first: you will look for the same name in the next steps. Malware that comes back after a restart is handled in the next two steps.
Step 3: Remove unknown login items and background items
Open System Settings > General > Login Items & Extensions. Under Open at Login and Allow in the Background, switch off or remove anything you do not recognize, especially items whose developer is shown as an unknown name or that appeared on the day you ran the command.
Then open Finder, choose Go > Go to Folder and check
~/Library/LaunchAgents,/Library/LaunchAgentsand /Library/LaunchDaemons for property list (.plist) files you did not add. Drag suspicious ones to the Bin, then restart the Mac.Step 4: Delete apps and downloads you did not intend to install
Open the Applications folder and your Downloads folder. Drag any app you did not install, and any disk image (
.dmg), installer (.pkg) or archive (.zip) that came from maple30.com or a site you do not trust, to the Bin, then empty the Bin.Also check
~/Library/Application Supportfor a folder with the same name as the app you removed.Step 5: Check the browsers for extensions and changed settings
In Safari open Settings > Extensions and General (homepage). In Chrome open
chrome://extensions, in Firefoxabout:addons.Remove any extension you did not add, and reset the homepage and search engine if they changed. Browsers hold saved passwords and cookies, which is why the password step comes first.
Step 6: If it was an infostealer, erase and reinstall macOS
Stealers copy data and often leave persistence you cannot be sure you found.
The only complete fix is to back up your personal files only (documents, photos, not apps or settings), then open System Settings > General > Transfer or Reset > Erase All Content and Settings, or use macOS Recovery to erase the disk and reinstall macOS, as Apple describes in its support articles.
Restore only your files afterwards, and install apps again from their official sources.
Step 7: Report it and watch your accounts
Report the site and the command to the authorities in your country, and tell your bank if any card was saved in a browser or in Keychain.
Over the next weeks watch your e-mail, bank and exchange accounts for sign-ins and transfers you did not make. Keep the notes you made, such as the process names and the file dates, in case a bank or the police ask for them.
Full procedure with screenshots: Report a cyber attack or scam to the authorities
Updates and a second opinion
The Mac has no scan that proves it is clean. Updates and a scanner help for later, but they do not undo what was already sent.
- 1
Install updates
Open System Settings > General > Software Update and install what is offered. Malwarebytes reports a Terminal warning on pasted commands in macOS Tahoe 26.4, which Apple has not documented.
- 2
Review file access
In Privacy & Security remove Terminal or any unknown app that has Full Disk Access or Automation rights you did not give.
- 3
Use a scanner as a second opinion
A Mac scanner may find known Amos files and login entries. A quiet result does not clear the Mac.
If your device is not a Mac
The tags and the .command file point at macOS.
| Device | What we know | What to do |
|---|---|---|
| Windows PC | A Mach-O program does not run on Windows. ClickFix also exists for PCs, with the Run box and PowerShell | If you pasted a command into Run or PowerShell, use our Windows guides |
| iPhone or iPad | No place to paste a command | Change passwords if you typed any on the page |
| Android | No source mentions it | Change passwords if you typed any on the page |
After removal: passwords, accounts and prevention
Recovery: accounts first, then the Mac
Follow this order: another device, then crypto, then the Mac.
- 1
Passwords from a clean device
On a phone or another computer, change your email password first, then banking, work and social accounts. Change your Apple Account password at account.apple.com.
- 2
Sessions and keys
Use each account's option to sign out everywhere. Revoke API tokens, SSH keys and cloud keys that were on the Mac.
- 3
Keychain
Treat every password in the login keychain as known to the attacker and change the important ones.
- 4
Crypto
If a recovery phrase was on the Mac, make a new wallet on a clean device and move the funds.
- 5
Two-factor sign-in
Turn it on with an authenticator app or a security key wherever the account offers it.
- 6
Erase and reinstall
Copy documents and photos only. Then use System Settings > General > Transfer or Reset > Erase All Content and Settings on a Mac with Apple silicon or a T2 chip, or erase the disk in macOS Recovery and reinstall. Set up as new.
- 7
Monitor
For several weeks watch your bank, mail and crypto, and tell your bank at once about anything you did not do.
How to avoid the next one
One rule covers it: a website never needs you to paste a line into Terminal.
Do
- Close any page that asks you to paste a command into Terminal.
- Keep macOS and your browser current.
- Get Mac apps from the App Store or the developer's own site.
- Keep a backup on a disk that is unplugged.
- Use an authenticator app for important accounts.
Don't
- Do not paste a command to pass a check or free disk space.
- Do not click Paste Anyway on a warning about a line you did not write.
- Do not type your Mac password into a window that appeared after a pasted line.
- Do not run cracked software installers.
- Do not take a quiet scan as proof you are safe.
Questions about maple30.com (Amos, ClickFix, macOS)
What is maple30.com?
It is a website that URLhaus lists for serving Mac malware, not a program on your computer. Four file addresses on it were added on 26 September 2026, one of them a Mach-O program tagged Amos and ClickFix.
The domain was registered on 14 August 2026. It shares an identical file address with quillchant14.com, which points to one operator behind both. On 10 October 2026 our visit got a Cloudflare error, so we cannot say what the site shows today.
If you only saw the name in a warning, you are not infected by that. If you ran a command or opened a file from it, use the steps on this page.
Is maple30.com safe to open?
Do not treat it as safe. Opening a page is not the same as running its command, but a malware host can show a convincing fake check and push you to paste a line into Terminal. Our own visit only got a Cloudflare error, which clears nothing, because malware sites often answer differently by country, device or tool.
Do not open files from it and do not paste anything it gives you. If you already visited and did nothing more, close the tab, clear the site data in your browser and carry on. The risk starts when a command is run.
What does Amos do to a Mac?
Amos is a family of Mac information stealers. Palo Alto Networks describes one infection that asked for the Mac password, then collected crypto wallet data, cloud and developer logins, shell history and Telegram data into an archive and uploaded it in stages.
We do not know that the file on maple30.com is Amos, since the tag comes from a reporter and we did not open the file. Treat it as a strong warning. Families like this change often, so details from one report may not match another.
What is ClickFix, and why does Terminal matter?
ClickFix makes you infect yourself. A page shows a fake check, a fix or a setup guide and tells you to copy a line and paste it into Terminal.
The line usually starts with curl and downloads a script that fetches the real malware. No security hole is used. Because you start the command, the first-open check that Apple applies to downloaded apps does not work as a barrier.
Palo Alto Networks notes that a fake toolkit setup page is not a strict ClickFix, but it uses the same paste step. The safe rule is simple: never paste a command from a web page.
I ran the command from this site. What now?
Turn off Wi-Fi and stop using the Mac for anything important. On a phone or another computer change your email password first, then banking, work and social accounts, and sign out of every session. Move crypto to a new wallet made on a clean device.
Revoke any cloud or developer keys that were on the Mac. Only then copy documents and photos to a drive and erase the Mac and reinstall macOS. Accounts come first because the data may already be gone, so they are at risk before the Mac is.
Why are maple30.com and quillchant14.com linked?
In our copy of the URLhaus feed the main Mach-O file has the same long path and the same tags on both domains, and the same reporter filed both entries on 26 September 2026, about 80 minutes apart. Both domains use the registrar Dominet (HK) Limited, and both answered our test with a Cloudflare error.
That fits one operator running two names for one file. It does not prove who the operator is, how many other names serve the file, or that the two sites look alike. Blocking one domain does not stop the other.
Will Gatekeeper or the Terminal warning protect me?
Not reliably. Apple says Gatekeeper is designed to help ensure that only trusted software runs on a Mac, and that it asks for approval before downloaded software opens for the first time. A command you paste starts the work from Terminal, so that prompt is not the barrier.
Malwarebytes reports that macOS Tahoe 26.4 shows a Possible malware, Paste blocked warning for some pasted commands, with a Paste Anyway choice. Apple has not documented it and it does not flag everything. Use both as a help, and keep the rule of never pasting a command from a page.
Can I just delete the files and be done?
No. Deleting a file removes the file, not the damage. A stealer takes your data in minutes and may remove itself, so the real risk is what was already sent:
- saved passwords
- sessions
- wallet data
- keys
Some Amos infections also leave hidden folders and login items that start the program again. If you ran the command, change your passwords from another device, move crypto, and erase the Mac and reinstall macOS. If you only opened the page and pasted nothing, there is nothing to delete.
How do I know whether I ran the command?
Think back to whether any page told you to open Terminal and paste something. If so, open Terminal and read the lines on screen. A long line with curl, a web address, base64, zsh or bash is the command.
Also ask yourself whether a password window appeared right after you pressed Return, and whether Terminal asked to control Finder or Notes or to reach Desktop and Documents. Check System Settings, General, Login Items & Extensions for items you did not add. If you are unsure, assume you did, because the cost of checking is small.
Will Fortect remove maple30.com?
Fortect for Mac scans for malware and unwanted programs, and its free scan shows what it finds on your Mac before you decide anything.
For maple30.com, follow the plan on this page as well: removing a launch item or an app is done in macOS itself, and a scanner cannot undo what was typed or entered on the infected Mac, such as saved passwords that were copied.
Change your passwords from another device first, and if the page tells you to erase the Mac, a scan is not a substitute. The free scan costs nothing and the full-featured product needs a license.
Sources
- URLhaus (abuse.ch): host page for maple30.com (entries read from our copy of the feed) (read October 10, 2026)
- RDAP registration record for maple30.com (read October 10, 2026)
- Palo Alto Networks Unit 42: Atomic macOS (AMOS) stealer activity (read October 10, 2026)
- Malwarebytes: New macOS security feature will alert users about possible ClickFix attacks (read October 10, 2026)
- Apple Platform Security: Gatekeeper and runtime protection in macOS (read October 10, 2026)