ClickFix Fake CAPTCHA Execution with Shell History Clearing
Detects ClickFix-style social engineering attacks where users are lured into executing obfuscated commands via terminal copy-paste. The detection monitors for the sequential execution of remote file downloads (e.g., curl, PowerShell) followed immediately by shell history-clearing commands designed to obfuscate the malicious activity. This behavior is associated with macOS crypto-drainers and loaders.
Sigma

