We’ve warned before about scams that trick users into pasting malicious commands into Terminal. Attackers create fake CAPTCHA pages—often resembling Cloudflare’s “are you a human” tests—that instruct visitors to open Terminal, paste a command, and press Return. Because the user executes the command themselves, macOS’s security protections are bypassed. Malwarebytes recently documented a macOS infostealer called Infiniti Stealer that spreads this way, stealing Keychain passwords, browser credentials, and cryptocurrency wallets. These attacks have become common enough that Apple has added a warning in macOS 26.4 Tahoe that appears when a user pastes a potentially dangerous command from Safari into Terminal. The protection is still in its early days—in our testing, the warning dialog appeared only once, with subsequent attempts producing only a beep. Worse, if you allow the first paste, Terminal keeps allowing pastes without further warnings. It’s a step in the right direction, but don’t count on it yet. The core advice remains: never paste commands into Terminal from websites unless you trust the site and fully understand what it does. No legitimate CAPTCHA ever requires Terminal commands!

(Featured image by iStock.com/thomaguery)

Picking one style guide and living with it is the advice I give every time this question comes up, and…
Golden Gate as the macOS 27 codename is a nice callback. For mixed households I'd love a recommendation on the…
Check with your phone service provider.
Do you take orders for the new 18 or is that just at the Apple stores? Thanks
Making Wi-Fi joining as easy as scanning a QR code is exactly the kind of MacWorks tip guests actually use.