The ClickFix attack displays an error notification from a compromised site, prompting the user to "fix" the display by coping a command into the terminal. When executed, it launches a hidden disk-image containing the Atomic macOS stealer. The stealer can then present the user with a fake authentication page to gain further access with user authorization. Then, the stealer can collect credentials, cookies, autofill passwords, and payment details, sending them to the attacker's server. Legitimate sites do not ask users to run terminal commands, so any terminal prompts from websites should be rejected.