A newly reported Mac threat known as ClickLock appears to rely on a simple social-engineering trick rather than a software bug. The attack starts with a fake verification page that looks like a routine "verify you are human" check, but instead of confirming access in a browser, it tells the user to open Terminal and paste in a command.
That instruction is the key warning sign. On a Mac, Terminal is used to run system commands, and normal website verification pages should not require it. If a user follows those steps, the malware can be installed through the command they entered themselves, giving the attackers a path onto the device.
According to the report, ClickLock can then go after sensitive information such as passwords and cryptocurrency wallets. It is also described as locking apps until the victim gives in, making the infection more disruptive than a typical fake web prompt and turning a simple browsing moment into a broader security problem.
The case is a reminder that Mac users are not immune to browser-based scams. Any page that suddenly asks for Terminal access, copied commands, or unusual system actions should be treated as suspicious, especially when it appears during a basic verification step.