macOS ClickFix AMOS Stealer: Pasted curl/base64 Pipe to Shell

Detects suspicious command execution patterns on macOS frequently associated with the 'ClickFix' technique utilized by AMOS (Atomic macOS Stealer). This includes piping base64-encoded curl downloads directly to a shell, utilizing osascript to execute shell commands, and modifications to LaunchAgents for potential persistence.