macOS ClickFix: curl|base64-decode piped into zsh/sh
Detects suspicious command execution patterns commonly associated with ClickFix-style social engineering attacks. The rule identifies Terminal processes executing shell commands that retrieve remote content via curl, followed by base64 decoding and/or piping directly into a shell interpreter (zsh/sh/bash), which is a common technique for executing obfuscated malicious payloads.
Sigma

