A routine web search led to a macOS malvertising campaign chaining ClickFix social engineering, blockchain-hosted C2 via EtherHiding, a 157-wallet infostealer, and a malicious Chrome extension, with its deployment infrastructure funded by 464.80 ETH withdrawn one way from a KuCoin hot wallet.