A large cluster of lookalike download domains is being used to selectively serve macOS users infostealer payloads, with the lure hidden behind browser fingerprinting and ClickFix-style social engineering.