tryclix.com: a Mac ClickFix site listed for the MacSync stealer, and what to do if you pasted its command

tryclix.com is a website that URLhaus lists for Mac malware downloads tagged ClickFix and MacSync, and our browser could not find the domain at all when we tested it. If you pasted a command from it into Terminal on your Mac, treat the Mac as compromised: change your passwords from another device, move any crypto, then erase and reinstall macOS.

Facts checked October 10, 2026. Removal steps checked against Apple's current documentation and the security vendors' reports. We have not run the malware on a Mac.

Automatic

Get a free scan and check if your Mac is infected.

Fortect for Mac scans for malware and unwanted programs, and its free scan shows what it finds before you decide anything.

Programs like a script or program from tryclix.com, or a command pasted from its page into Terminal usually arrive in groups; a free scan lists the companions that are easy to miss.

Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free.

Do it yourself · free Remove tryclix.com (ClickFix, MacSync, macOS) yourself 7 steps, about 21 minutes, no software needed.

Start the steps
Table of three URLhaus entries for tryclix.com added on 26 September 2026: a zsh script, an AppleScript and a Mach-O backdoor, all tagged ClickFix, macOS and MacSync and all offline
The three URLhaus entries for tryclix.com that we read on 10 October 2026, with the long token shortened. Our own browser could not resolve the domain, so this table of reports, not a screenshot of the site, is the main evidence.

Tryclix.com (ClickFix, MacSync, macOS): summary

TypeA malware download address for Macs: URLhaus lists a zsh script, an AppleScript and a Mach-O backdoor, all tagged ClickFix and MacSync
RiskHigh if you pasted its command or opened its files: passwords, sessions, crypto and developer keys may have been taken
SymptomsOften none. A strange line in the Terminal history, an unexpected password window or an unknown Login Item are the signs
How to get rid of itDisconnect, change passwords from another device, move crypto, back up documents, then erase the Mac and reinstall macOS
Our check (10 October 2026)One visit: the domain did not resolve, no page. A quiet or missing site clears nothing; the danger rating comes from URLhaus
Running since / first seenDomain registered 4 March 2025; first malware URLs reported 26 September 2026
Removal

Scan the Mac with security software to find the malware and anything installed with it. Fortect for Mac scans for malware and unwanted programs.

Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free.
Show 9 more facts
PlatformmacOS, by the tags macOS, zsh, AppleScript and Mach-O
Detection namesNo Microsoft detection name is known for the files on this server, because we did not open them and we did not check them against Microsoft's list. The URLhaus tags are ClickFix, MacSync, macOS, zsh, AppleScript, Mach-O and backdoor
NameTryclix.com
Domain registered4 March 2025
Evidence3 write-ups by security sites; details still limited
First seen26 September 2026
DistributionTypically fake installers, cracked programs, e-mail attachments, fake "verify you are human" pages and ads for popular apps
DamageInstalls other malware, often several programs at once
Facts checked10 October 2026

Facts checked on 10 October 2026 against our copy of the URLhaus data for tryclix.com, RDAP, one browser visit of our own, Moonlock, the Center for Internet Security and Apple Platform Security. We did not download the files and we infected no Mac; the removal steps and menu paths were not tried on a live infection.

What tryclix.com is, and what we know about it

tryclix.com is known to us only through three malware addresses that a URLhaus reporter added on 26 September 2026. We never saw the page that visitors see, so this guide says plainly which parts are reports and which parts are our own checks.

  1. 1

    What URLhaus lists

    Three addresses on tryclix.com, all added on 26 September 2026 at about 06:23 UTC by the reporter c4ffeine. One sits under /curl/, one is /dynamic with a txd value, and one sits under /loader/agent/. Each ends in the same 64 character token, which starts with b54cc90c. All three are marked malware_download and all three were offline when we read them.

  2. 2

    What the tags mean

    ClickFix is a trick in which a fake page makes you copy a command and run it yourself. MacSync is the name of a Mac information stealer. zsh is the shell that Terminal uses on a modern Mac, AppleScript is the Mac scripting language, and Mach-O is the program format of macOS. Together the tags describe a pasted command that pulls a script, a second script and a program.

  3. 3

    What we could not confirm

    We did not download any file and we never saw the page that tells visitors what to paste. So we do not know the lure, what the scripts do, or whether the three files really belong to MacSync. The labels are the reporter's, not our own findings.

  4. 4

    What this means for you

    If you only saw the name in a log, a link or a warning, that alone did not infect you. The risk is for people who pasted a command from the site into Terminal, or who opened a file from it.

Kind of threat
A malware download address for Macs, tagged ClickFix and MacSync
Delivery trick
ClickFix: a fake page asks you to copy a command and paste it into Terminal
Domain registered
4 March 2025, expires 4 March 2027, registrar Unstoppable Domains Inc.; record last changed 26 September 2026 (RDAP, read 10 October 2026)
URLhaus entries
3 file addresses, all added on 26 September 2026, all offline when we read them
Platform
macOS, by the macOS, zsh, AppleScript and Mach-O tags

What tryclix.com (ClickFix, MacSync, macOS) does on an infected Mac

What we checked on 10 October 2026, and what we could not

We tried to open https://tryclix.com/ once, from Lithuania, in an automated Chromium browser set to English. The browser could not find the domain. That tells you nothing good about the site, and it clears nothing.

Our site test, 10 October 2026

  • The domain did not resolveThe browser reported ERR_NAME_NOT_RESOLVED. In plain words, the name tryclix.com gave no address on this one visit. We did not get a web page, a certificate or a single byte from the site.
  • Why that is not a clean resultA name that does not resolve can mean the operators or the registrar switched it off, that the record was removed, or that a lookup failed. We cannot tell which from one visit. Operators also change names often, and the same campaign may live on other domains.
  • Notification request, pop-ups, redirects, ad networksNone seen. There was nothing to see: no page loaded on this one visit.
  • URLhaus listingThree malware addresses on this domain, all marked offline when we read the database.
  • Downloads and the page itselfWe did not download the files and we did not reach any page that shows a command. We cannot tell you what the scripts do.

Dangerous: treat it as a malware site The site test was one visit that found no domain, so it proves nothing either way. The danger rating comes from the URLhaus reports, not from our visit. Do not open files from this name, and do not run anything it gives you.

What happened to tryclix.com, from registration to our test

This domain is not new. It was registered in March 2025, more than a year before the reports, so a young domain is not the warning sign here. The dates come from RDAP and from the URLhaus database.

  1. 4 March 2025

    The domain is registered

    RDAP shows tryclix.com registered on 4 March 2025 through Unstoppable Domains Inc., valid until 4 March 2027. We found nothing that shows a real business behind the name, and we do not know who held the domain in 2025.

  2. 26 September 2026

    Three files are reported in one batch

    At about 06:23 UTC the reporter c4ffeine adds three addresses to URLhaus, with the tags ClickFix, macOS and MacSync. The same day RDAP shows the domain record changed. We do not know whether the two events are connected.

  3. 10 October 2026

    Our test finds no address for the name

    Our single visit fails with a name resolution error. When we read the database all three addresses are marked offline.

Two weeks passed between the reports and our test. A domain that stopped answering inside that window may have been taken down, or it may have been left behind by the operators on purpose. A name that no longer answers does not remove the risk for a Mac that already ran the command.

How the ClickFix trick works on a Mac

ClickFix does not use a security hole. It makes you do the infecting yourself, so the checks that Apple builds into downloads may never get a say. We did not see tryclix.com's page; this is how Moonlock and the Center for Internet Security describe MacSync campaigns.

Three stages suggested by the tryclix.com addresses: a zsh script under curl, an AppleScript under dynamic and a Mach-O program under loader and agent
The three stages that the tags and paths of the tryclix.com addresses suggest. This is our reading of the URLhaus data, not something we downloaded.
  1. 1

    You land on a page with a reason to open Terminal

    Moonlock describes a fake Cloudflare Turnstile check that tells you to copy a command. The Center for Internet Security describes a fake CAPTCHA reached from a search result for a free e-book. The reason differs; the goal is the same.

  2. 2

    The page copies a command for you

    In the CIS case the pasted line was Base64 text. Decoded, it printed the message Installing package please wait while it quietly ran a curl command. In Moonlock's case the pasted text was an obfuscated AppleScript that ran in the background.

  3. 3

    You open Terminal and paste

    The page tells you to open Terminal, press Command + V and press Return. Terminal runs the line with your rights. Nothing was opened through Finder, so the first open check described below never has the chance to act.

  4. 4

    A script fetches the next stage

    CIS describes a zsh script fetched by curl with a 64 character token in the address. The token ties the download to one visitor and helps the operators block analysis machines. This matches the long token that ends all three tryclix.com addresses.

  5. 5

    An AppleScript asks for your password and collects files

    CIS saw the AppleScript run in memory through osascript, close Terminal, show a fake window called Required Application Helper that asks for the Mac password with no cancel button, and pack the data into a zip file in /tmp.

Apple says Gatekeeper is designed to help ensure that only trusted software runs on a Mac, and that it asks for approval before downloaded software opens for the first time. Apple's page does not say how this applies to a command you paste yourself, so we do not claim that it would have stopped this.

The three addresses: what each suggests, and what we do not know

Paths and tags are weak evidence. We list what each address could be and mark which statements are only a reading.

Source: our copy of the URLhaus data, read 10 October 2026. The right hand column is our own reading.
Address on tryclix.comWhat URLhaus saysWhat it may be (our reading)
/curl/ followed by the tokenOffline. Tags: ClickFix, macOS, MacSync, stage1, stealer, token, UnstoppableDomains, zshThe first stage, a zsh script that the pasted curl line downloads and runs. stage1 is the reporter's label
/dynamic with txd equal to the tokenOffline. Tags: AppleScript, ClickFix, macOS, MacSync, stealer, token, UnstoppableDomainsA second stage in AppleScript. In the CIS case a script of this kind asked for the password and gathered data
/loader/agent/ followed by the tokenOffline. Tags: backdoor, ClickFix, Mach-O, macOS, MacSync, stealer, token, UnstoppableDomainsA Mac program tagged as a backdoor. Moonlock reports that MacSync gained a backdoor in 2025. We cannot say what this file does

The same token in all three addresses says they were made for one visitor session, or at least for one build of the chain. It does not say how many people received them. URLhaus does not show a victim count and neither do we.

What tryclix.com (ClickFix, MacSync, macOS) can steal or download

What MacSync is and what a Mac stealer takes

We do not know that the programs on this server are MacSync, only that a reporter tagged them so. Here is what Moonlock and the Center for Internet Security publish about MacSync infections, as a guide to what may be at stake.

Six groups of data that MacSync took in a published case: browser data, crypto wallets, Keychain and keys, messages and notes, user files and a replaced Ledger Live app
What the Center for Internet Security says MacSync took in one campaign. It is not a test of tryclix.com.

What CIS lists as taken in a MacSync campaign

  • Cookies, saved logins and extension data from 13 Chromium based and 4 Gecko based browsers
  • Data from more than 80 wallet extensions and more than 20 desktop wallet apps
  • The macOS Keychain, SSH private keys, AWS credentials and Kubernetes configs
  • The whole Telegram Desktop data folder and the shell history
  • Safari cookies and history, Apple Notes, and files in Desktop, Documents and Downloads
Sources: Moonlock Lab on MacSync (published 12 September 2025) and the Center for Internet Security on a MacSync campaign, both read 10 October 2026.
PointWhat it means for youSource
Where it came fromMoonlock reports a developer using the name mentalpositive released the stealer as mac.c in April 2025, and that it was renamed MacSync about a month later and gained a backdoor written in GoMoonlock
How it is soldCIS says the stealer is leased to other criminals. So the people who run a page like this one may not be the people who wrote the programCenter for Internet Security
Password promptThe stealer asks for your Mac password in a fake window. Typing it hands over the key to the Keychain and to anything that needs an administratorCenter for Internet Security
Staging and uploadData was packed in a zip file in /tmp and uploaded in 10 MB pieces. Moonlock saw a zip called salmonela in /tmp in its sampleCIS and Moonlock
BackdoorMoonlock reports a Go program that polls a server every few seconds for commands and ran a test command it was given. It describes no way for that program to restart itselfMoonlock
Hardware walletsCIS reports that the Ledger Live app was replaced with a version that sends seed phrases to the attackers, and that it keeps doing so after the stealer is goneCenter for Internet Security

What this can cost you

Reading the site name or seeing a warning costs nothing. The risks below apply to a Mac where the command was pasted and run, or a file from the site was opened.

  • High

    Account takeover

    A stealer takes saved logins and browser sessions, which let someone use your email, social and work accounts. Changing a password alone may not end a stolen session.

  • High

    Crypto theft

    Wallet files and wallet apps are a main target. Stolen crypto cannot be reversed, so move funds from a clean device before you do anything else on the Mac.

  • High

    A replaced wallet app

    If you use Ledger Live on that Mac, CIS says the app can be swapped for a copy that steals the seed phrase each time it opens. Treat that wallet as exposed.

  • High

    Developer and cloud keys

    SSH keys, AWS credentials and shell history were taken in the published case. A key found there can be used to read data or run services on your bill.

  • Medium

    A backdoor that takes orders

    The reporter tagged one file as a backdoor. If it ran, someone may be able to send commands to the Mac until it is erased.

  • Medium

    Work accounts and company data

    On a work Mac the passwords and sessions in the browser reach company systems. Tell your IT or security team at once; they can block the accounts.

  • Low

    Nothing, if you only saw the name

    A name in a warning, a firewall log or a blocked link is not an infection.

What you may notice, and what you may not

Most victims notice nothing. The signs below follow from how these chains work; the first two are the best evidence you have.

Sources: Center for Internet Security and Moonlock for the prompts and messages; the rest follows from how the chain works.
SignWhat it means
A line in Terminal that you did not writeTerminal keeps its history. Open it and scroll up: a long line with curl, a web address, base64, zsh or osascript is the command that was pasted
A password window that you did not expectA window called Required Application Helper, or any prompt for your Mac password right after you pressed Return in Terminal, is how CIS says the stealer gets the password
Terminal closing by itselfCIS says the AppleScript closes Terminal after it starts. A window that vanishes right after you paste is a reason to look
A fake message that the app is not supportedCIS reports a message that says your Mac does not support the application, shown to hide the upload
Items you did not add in Login ItemsEntries show up in System Settings under General, Login Items & Extensions, or as files in the LaunchAgents folders. The sources we read do not describe persistence for the stealer, so a clean list does not clear the Mac
Accounts you did not touchLogins from new places, password reset emails and messages sent from your accounts. This follows from stolen sessions; it is our reading, not a quote
Missing cryptoBalances that fall after the infection
Nothing at allStealers are built to finish in minutes and stay quiet

How to check the Mac for tryclix.com (ClickFix, MacSync, macOS)

How people end up on a page like this

We do not know how visitors reached tryclix.com. These are the routes that the sources we read describe for MacSync and ClickFix pages in general.

  1. 1

    A search result for something free

    CIS describes a poisoned search result for a free e-book that led to a fake CAPTCHA. Searches for cracked software and free tools lead to the same kind of page.

  2. 2

    A fake Download for macOS button

    Moonlock describes a page whose download button does not download a file. It shows instructions that end with a command to paste.

  3. 3

    A fake verification step

    A page claims that you must prove you are human by pasting something. A real check such as Cloudflare Turnstile never asks you to open Terminal.

  4. 4

    A link you were sent

    A message, an ad or a hacked website can point to the page. The page can look different for each visitor, which is one more reason our single test proves little.

Check your Mac before you delete anything

These checks help you decide whether the command ran. They are not a way to prove that a Mac is clean. If you pasted the command, go to the next chapters whatever you find.

  1. 1

    Read the Terminal history

    Open Terminal and type history, then press Return. Look for a long line with curl, a web address, base64, zsh or osascript that you did not write. You can also open the file .zsh_history in your home folder. The history may be cut if Terminal was closed in an unusual way.

  2. 2

    Look at Login Items

    On macOS Ventura and later, open System Settings, choose General, then Login Items & Extensions. Read both the list that opens at login and the list that runs in the background. Remove nothing yet; write down what looks unknown.

  3. 3

    Look in the LaunchAgents folders

    In Finder choose Go, then Go to Folder, and open ~/Library/LaunchAgents, then /Library/LaunchAgents and /Library/LaunchDaemons. Files with names that you do not know, or that pretend to be Apple, deserve a closer look.

  4. 4

    Look in /tmp for staging folders

    CIS names a staging folder that starts with sync followed by seven digits, and a zip called osalogging. Moonlock names a zip called salmonela. The stealers delete their files after the upload, so an empty /tmp proves little.

  5. 5

    Remember what a clean check means

    Finding nothing means only that these places were quiet. Stealers delete their traces and a backdoor may sit somewhere else. If you pasted the command, erase the Mac.

How to remove tryclix.com (ClickFix, MacSync, macOS)

How to remove tryclix.com from a Mac

Start with the passwords and crypto, from another device: a stealer copies them in seconds.

Then clean the Mac, or erase it.

  1. Step 1: Change passwords from another device first

    If you pasted a command into Terminal or opened a downloaded file from tryclix.com, assume the passwords saved in the browsers and in Keychain on this Mac are known to the attacker.

    From a phone or a clean computer, change the e-mail password first, then banking, shopping, social and work accounts, and sign out of all other sessions on each one.

    Move any cryptocurrency to a new wallet created on a clean device, because a seed phrase that was stored on this Mac is compromised. Do this before cleaning the Mac: cleaning does not undo the theft.

    Full procedure with screenshots: Turn on two-step verification / secure a hacked account

  2. Step 2: Quit what is running that you do not recognize

    Open Activity Monitor (in Applications > Utilities, or search for it with Command + Space).

    In the CPU or Network tab, look for a process you did not install or whose name is random, select it, click the stop button (the octagon with an X) and choose Quit or Force Quit.

    Note the name first: you will look for the same name in the next steps. Malware that comes back after a restart is handled in the next two steps.

  3. Step 3: Remove unknown login items and background items

    Open System Settings > General > Login Items & Extensions. Under Open at Login and Allow in the Background, switch off or remove anything you do not recognize, especially items whose developer is shown as an unknown name or that appeared on the day you ran the command.

    Then open Finder, choose Go > Go to Folder and check ~/Library/LaunchAgents, /Library/LaunchAgents and /Library/LaunchDaemons for property list (.plist) files you did not add. Drag suspicious ones to the Bin, then restart the Mac.

  4. Step 4: Delete apps and downloads you did not intend to install

    Open the Applications folder and your Downloads folder. Drag any app you did not install, and any disk image (.dmg), installer (.pkg) or archive (.zip) that came from tryclix.com or a site you do not trust, to the Bin, then empty the Bin.

    Also check ~/Library/Application Support for a folder with the same name as the app you removed.

  5. Step 5: Check the browsers for extensions and changed settings

    In Safari open Settings > Extensions and General (homepage). In Chrome open chrome://extensions, in Firefox about:addons.

    Remove any extension you did not add, and reset the homepage and search engine if they changed. Browsers hold saved passwords and cookies, which is why the password step comes first.

  6. Step 6: If it was an infostealer, erase and reinstall macOS

    Stealers copy data and often leave persistence you cannot be sure you found.

    The only complete fix is to back up your personal files only (documents, photos, not apps or settings), then open System Settings > General > Transfer or Reset > Erase All Content and Settings, or use macOS Recovery to erase the disk and reinstall macOS, as Apple describes in its support articles.

    Restore only your files afterwards, and install apps again from their official sources.

  7. Step 7: Report it and watch your accounts

    Report the site and the command to the authorities in your country, and tell your bank if any card was saved in a browser or in Keychain.

    Over the next weeks watch your e-mail, bank and exchange accounts for sign-ins and transfers you did not make. Keep the notes you made, such as the process names and the file dates, in case a bank or the police ask for them.

    Full procedure with screenshots: Report a cyber attack or scam to the authorities

What a scan can and cannot do on a Mac

A scanner can add information. It cannot give you a reason to skip the steps that protect your accounts.

  1. 1

    Update macOS first

    Open System Settings, General, Software Update and install what is offered. Apple updates its built in malware checks with the system. Do this on a Mac that you will keep using, and do it after you change passwords from another device.

  2. 2

    Check what is allowed to read your files

    In System Settings choose Privacy & Security, then Full Disk Access, Accessibility and Automation. Remove entries for apps that you do not know. Terminal needs none of these for normal use unless you gave them yourself.

  3. 3

    Run a scanner that reads the Mac

    A Mac security scanner can look for known samples and for files in the places above. A result of nothing found does not clear a Mac that ran a stealer, since the files may already be deleted and the damage is the data that left.

  4. 4

    Do not stop there

    The loss happens in the first minutes. After a scan, continue with passwords, sessions, keys and the erase.

If you use Windows, an iPhone or an Android phone

The three addresses are tagged for macOS only. A Mac command does not work on other systems, but your accounts may be shared across them.

DeviceWhat to do
Another Mac that you did not use for thisNo action for the files. Change the same passwords from it, since sessions that were taken work from any device
Windows PCA Mac line does not run there. If you opened the page on Windows, close it. Windows pages with the same trick paste PowerShell instead, and our Windows guides cover those
iPhone or iPadNothing in the reports targets iOS. Use the phone to change passwords and to check where your Apple Account is signed in
Android phoneNothing in the reports targets Android. Use the phone for two step codes only if it is not signed in to the same accounts that were exposed

After removal: passwords, accounts and prevention

After a clean Mac: protect what was taken

Do these in this order and from a device that did not run the command. A phone or another computer is enough.

  1. 1

    Disconnect the Mac

    Turn off Wi-Fi and unplug Ethernet so that nothing more is sent out. Do not type a password on that Mac again until it has been erased.

  2. 2

    Move crypto first if a wallet was on the Mac

    From a clean device, create a new wallet with a new seed phrase and move the funds. If you used Ledger Live on that Mac, treat its seed phrase as exposed even after the Mac is clean.

  3. 3

    Change passwords from a clean device

    Start with the email account that resets all others, then banks, then work and social accounts. Use a new password for each.

  4. 4

    Treat the Keychain as exposed

    Every password saved in iCloud Keychain, Passwords or the browser can be assumed to be known. Change them in the order of what they protect.

  5. 5

    Sign out other sessions and revoke keys

    In each important account, choose the option to sign out everywhere. Revoke SSH keys, access tokens and cloud keys that were on the Mac and make new ones.

  6. 6

    Turn on two factor sign in

    Use an authenticator app or a hardware key, not only a text message.

  7. 7

    Back up documents and erase the Mac

    Copy only documents and photos to an external disk, not apps or settings. On macOS Sonoma and later open System Settings, General, Transfer or Reset, then Erase All Content and Settings. On older versions use Recovery and Disk Utility. Then reinstall macOS and restore documents only. We did not test these menu paths on an infected Mac.

  8. 8

    Watch your accounts

    For some weeks read the sign in alerts of your email, bank and exchange accounts, and report any charge you did not make.

Keep a Mac out of this kind of trap

The rule that would have stopped this site is one line: a website never needs you to paste something into Terminal.

Do

  • Treat a request to paste a command into Terminal from a web page as an attack. Close the tab.
  • Keep macOS and your browser up to date.
  • Install Mac apps from the App Store or from the developer's own site, and open them the normal way.
  • Keep a backup of documents on a disk that you unplug.
  • Use an authenticator app for your important accounts, and keep a hardware wallet seed phrase off the computer.

Don't

  • Do not copy and paste a command to pass a check, to fix a Mac or to free disk space.
  • Do not type your Mac password into a window that appeared after a pasted command.
  • Do not run files from sites that promise free versions of paid software.
  • Do not open a wallet app again on a Mac that ran the command.
  • Do not rely on a quiet scan to say that you are safe.

Questions about tryclix.com (ClickFix, MacSync, macOS)

What is tryclix.com?

tryclix.com is a web address that the URLhaus database lists for Mac malware downloads. A reporter added three addresses on 26 September 2026 with the tags ClickFix, MacSync, macOS, zsh, AppleScript and Mach-O. The domain was registered on 4 March 2025 through Unstoppable Domains Inc.

When we tried to open it on 10 October 2026 our browser could not find the domain, so we never saw the page that visitors see. We do not know what the page says, who runs it or how many people received the files.

What we can say is that the reports describe a chain that begins with a command pasted into Terminal. If you are only reading about the name, nothing has happened to your Mac.

Is tryclix.com a virus?

No, a website is not a virus, but the files it handed out may be malware. URLhaus lists three addresses on tryclix.com as malware downloads, and one of them is tagged as a backdoor and a Mach-O program, which is a Mac program.

Visiting a page does not usually run those files. The danger comes when you paste a command from the page into Terminal or open a file it gave you. We did not download the files, so we cannot say what they do.

Our rating of dangerous rests on the URLhaus reports, because our own visit failed. Do not open anything from this name, and do not read the failed visit as proof that it is harmless.

What does ClickFix mean on a Mac?

ClickFix is a trick in which a web page convinces you to copy a command and run it yourself. On a Mac the command goes into Terminal.

Moonlock describes a fake Cloudflare Turnstile check, and the Center for Internet Security describes a fake CAPTCHA, that told visitors to paste a line. The line downloads a script with curl and runs it. Because you started the command, no download warning appears and no security hole is needed.

The rule that protects you is simple: a real website check never asks you to open Terminal and paste something. If a page asks, close it. If you already pasted the line, treat the Mac as compromised and follow the chapter on what to do next.

I pasted the command. What do I do first?

Disconnect the Mac from the network, then use another device for everything that follows. Do not type a password on the infected Mac. If you keep crypto, move it first from a clean device to a new wallet, since stolen coins cannot be returned.

Then change your email password, then banks, then other accounts, and choose the option to sign out all sessions. Revoke SSH keys, tokens and cloud keys that were stored on the Mac.

After that, copy only your documents to an external disk, erase the Mac, reinstall macOS and restore documents only. This order matters, because the stealer works in the first minutes and the data it took is the real loss.

What is MacSync, the stealer named in the reports?

MacSync is the name of a Mac information stealer. Moonlock reports that a developer using the name mentalpositive released it as mac.c in April 2025, and that it was renamed MacSync about a month later and gained a backdoor written in Go. The Center for Internet Security says it is leased to other criminals.

In a published campaign it took browser data, wallet data, the Keychain, SSH keys, cloud keys, Telegram data, notes and files. We did not confirm that the files on tryclix.com are MacSync; the label comes from the URLhaus reporter. Treat it as a strong hint, and judge your risk by whether you ran the command.

Will Apple's Gatekeeper or XProtect stop this?

We cannot promise that. Apple says Gatekeeper is designed to help ensure that only trusted software runs on a Mac, and that it asks for approval before downloaded software opens for the first time. The Apple page we read does not say how this applies to a command that you paste into Terminal, and it does not describe XProtect.

In a ClickFix attack you start the command yourself, which is why the sources describe it as a way around the usual download checks. Do not count on a built in check after you paste an unknown line. Keep macOS updated, and treat the paste itself as the point of no return.

The site does not load. Am I safe?

A site that does not load makes new infections from that name less likely, but it does not help a Mac that already ran the command. When we tested on 10 October 2026 the domain did not resolve, and all three URLhaus entries were offline.

That may mean the operators or the registrar switched it off, or that we hit a lookup failure. The same campaign can move to other domains, and a page can show a different thing to each visitor.

If you ran the command before the site went down, the stealer has already done its work and the steps for passwords, crypto and the erase still apply. If you did not, you are not infected by the name alone.

Can I just delete the files and be done?

No. Deleting a file removes a program but does not bring back anything that the program already sent away. CIS says the stealer uploads its data and then deletes its own traces, so there may be little to delete anyway. A backdoor, if it ran, can also have put other things on the Mac.

And a replaced wallet app can keep stealing after the stealer is gone. Deleting files you find is fine as a first look, but the safe way to end a compromise is to change every password from another device, move crypto, and erase the Mac. Without that you cannot know what is still running.

Do I need to reinstall macOS?

If you pasted the command and it ran, yes, we advise it. The reports tag one file as a backdoor, and a backdoor lets someone run commands on the Mac. No scanner can prove that such a Mac is clean, and the sources we read do not give a full list of what was left behind.

On macOS Sonoma and later, open System Settings, General, Transfer or Reset, then Erase All Content and Settings, and reinstall macOS. Restore documents only, not apps or settings. If you did not paste anything and did not open a file from the site, you do not need to erase the Mac.

Will Fortect remove tryclix.com?

Fortect for Mac scans for malware and unwanted programs, and its free scan shows what it finds on your Mac before you decide anything.

For tryclix.com, follow the plan on this page as well: removing a launch item or an app is done in macOS itself, and a scanner cannot undo what was typed or entered on the infected Mac, such as saved passwords that were copied.

Change your passwords from another device first, and if the page tells you to erase the Mac, a scan is not a substitute. The free scan costs nothing and the full-featured product needs a license.

Sources

More removal guides

Remove Android Charging Boost

Android Charging Boost blue lock screen is an intrusive problem for Android users triggered by PUPs and malware Android Charging Boost is an unwanted lock screen that emerges on AndroidMalwareHigh riskLinas Kiguolis ·

Remove Ghost Push virus

Ghost Push virus - a dangerous cyber attack that gains root access of Android devices Ghost Push virus is malware designed to infiltrate Android OS tablets and phones exclusively. ItMalwareHigh riskAlice Woods ·

Remove nordertextil.de: a ClickFix loader site for Windows, and what to do if you pasted its PowerShell command

nordertextil.de is a German web address that URLhaus lists for four malware downloads tagged ClickFix, Loader, exe and powershell, and our browser could not find the domain when we tested it. If you pasted a command...TRHigh riskUgnius Kiguolis ·

Remove swatting.wiki: a Mirai botnet download address for routers and cameras, and what to do if a device of yours may be infected

swatting.wiki is a web address that URLhaus lists for 14 malware downloads, every one tagged mirai, a botnet that takes over routers, cameras and other small network devices. The name no longer resolves when we look...TRHigh riskUgnius Kiguolis ·

Questions and experiences: tryclix.com (ClickFix, MacSync, macOS)

Still seeing it, or found something we did not cover? Ask here: members and our editors answer. Reading is open; writing needs a free account.

0 comments

…

5,449 members already hereReading, writing, commenting and voting. 0 verified · 174 joined this year