ArtHouse Cloud Logs MacOs v1 uploaded by a Telegram User
235,529 credential records from macOS devices hit a public Telegram channel on August 8, 2025. The file was labeled ArtHouse Cloud Logs MacOs v1, and it was not a small or generic dump. It was specifically generated by infostealer malware targeting Apple devices, which made it notable in a threat landscape that still tends to underestimate Mac-focused attacks. Every record in the file included an email address, a plaintext password, and the URL where that password was being used, pulled directly from compromised macOS endpoints.
Why This Is Dangerous
macOS users are often told their devices are more secure than Windows machines, and that perception leads to relaxed security habits. This leak challenges that directly. The ArtHouse Cloud Logs MacOs v1 file proves that infostealers are actively and successfully targeting Apple devices at scale. With 235,529 records and plaintext passwords throughout, this is exactly the kind of data that fuels credential stuffing campaigns, account takeovers, and deeper infrastructure compramise through the included API host information. The macOS-specific nature of this log suggests a targeted campaign rather than a broad spray-and-pray operation.
What Was Exposed
- 235,529 total records harvested from compromised macOS endpoints
- Email addresses for each affected account
- Plaintext passwords requiring no further processing to use
- URLs identifying the exact services and sites targeted per credential
- API host information linking to backend and cloud service access points
- Endpoint metadata from the infected Apple devices
Why This Matters
The scale here is significant. At over 235,000 records, this is one of the larger macOS-specific stealer logs to have surfaced publicly. The inclusion of API host data alongside credentials is particuarly worrying for organisations whose employees use Macs. Developer machines, creative workstations, and executive laptops running macOS are common in certain industries, and those devices often have access to sensitive systems and cloud environments. If any of the compromised users had admin access or developer credentials stored on their machines, the blast radius from this log goes well beyond individual account takeovers.
How Stealer Logs Work
macOS-targeting infostealers have grown significantly more sophisicated in recent years. They are typically delivered through fake application installers, cracked software distributed on torrent sites, or phishing messages with malicious attachments designed to look like legitimate tools. Once running on an Apple device, the malware accesses the macOS Keychain, browser saved passwords, and stored credentials in applications like Slack, Notion, or cloud sync tools. All of that data gets compiled into a structured log and exfiltrated to a remote server. The operator then packages the logs and posts them to Telegram channels, exactly as happened with ArtHouse Cloud Logs MacOs v1 in August 2025.
Check If You Are Affected
235,529 records is a lot of people. If you use a Mac and store passwords in your browser or in apps, your credentials may have been in this file. Heroic.com has indexed over 400 billion leaked records from breaches and stealer logs around the world, including this one. Search your email address for free right now to find out if your data has been exposed, which breaches it appeared in, and what you need to do next to secure your accounts.
Breach Breakdown
235,529 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds