NovaStealer is a macOS information stealer that targets cryptocurrency wallet data, browser cookies and login information, SSH keys, cloud credentials, and application configuration secrets. NovaStealer v2 has been linked to the Atomic macOS Stealer family and searches for data associated with more than 60 cryptocurrency wallets, including MetaMask, Phantom, Exodus, and Electrum. It exfiltrates wallet-related files, collects system telemetry, and replaces legitimate Ledger and Trezor applications with tampered copies.
Its execution chain uses a dropper to install an orchestrator, establishes persistence through a LaunchAgent, and retrieves Base64-encoded scripts from command-and-control infrastructure for execution in detached terminal sessions. NovaStealer has been distributed through the ClawHavoc supply-chain campaign targeting OpenClaw's ClawHub skill registry. Malicious skills masquerade as developer, cryptocurrency, and automation tools and use ClickFix lures involving fake fixes or purported companion security tools to persuade users to execute commands that download the malware.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The campaign coincides with the disclosure of a high-severity OpenClaw vulnerability (CVE-2026-25253) that enables one-click remote code execution through token exfiltration and WebSocket hijacking. Although patched in late January 2026, the flaw points to the platform’s growing attack surface.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
That command fetched NovaStealer v2, a macOS-focused information stealer linked to the Atomic macOS Stealer family.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
"distribution of MacOS stealers builds via curl payloads, in a ‘Clickfix’ style" and "creating utilities inside the panel to generate curl payloads."
7 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An information stealer reportedly delivered through malicious OpenClaw ClawHub skills in the ClawHavoc supply-chain campaign.
A macOS-focused information stealer delivered via malicious OpenClaw marketplace packages and ClickFix-style social engineering. It steals data from more than 60 cryptocurrency wallets and also collects browser cookies, login information, SSH keys, cloud credentials, and .env files.
Malware delivered through ClickFix social-engineering lures involving fake fixes and companion tools, in the context of the ClawHavoc campaign targeting the OpenClaw skill ecosystem. The content does not describe its specific collection capabilities.
A named macOS stealer family appearing at low prevalence in the reporting period.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.