SentinelOne researchers have detailed a new macOS infostealer variant called SHub Reaper that impersonates Apple, Google, and Microsoft across a single attack chain. Unlike earlier SHub variants that relied on Terminal-based ClickFix tactics, Reaper abuses the applescript:// URI handler to pre-populate malicious AppleScript in Script Editor, bypassing Apple's recently introduced Terminal paste protections. The malware uses fake Apple security alerts to initiate execution, Google-themed interfaces for legitimacy, and typo-squatted Microsoft domains for payload hosting. Once active, it harvests browser credentials, password manager data, Keychain data, cryptocurrency wallets (MetaMask, Phantom), and user documents. Defenders are advised to monitor for unusual Script Editor and osascript activity, suspicious LaunchAgent persistence entries, and implement web filtering against typo-squatted domains.