ClickLock Stealer shows how a pasted command, not a zero-day, can become the most dangerous part of a macOS infection path.