In the quiet architecture of everyday trust, a new macOS threat called AmnesiaStealer exploits the simple act of following instructions — luring users through counterfeit GitHub pages into pasting a command that opens the door to credential theft, file exfiltration, and ultimately, live remote control of their own browser. Identified by Jamf researchers in mid-August 2026, the malware represents a maturation of social engineering on Apple platforms: not a brute-force intrusion, but a patient manipulation of human habit. Its second stage, capable of puppeteering a victim's logged-in browser ses