is a newly discovered Rust-based macOS malware distributed via a fake GitHub page using ClickFix-style social engineering, tricking victims into running a malicious Terminal command. Once installed, it harvests sensitive data including browser databases, keychains, Apple Notes, and documents, while also attempting to bypass macOS's TCC framework to gain broader access. A particularly notable feature is its remote-control "stream module," which uses the Chrome DevTools Protocol to launch a hidden browser session, giving attackers live, interactive control over the victim's browsing activity.