ClashMac 27: a closed-source SwiftUI proxy client for macOS 15
Native Proxy Experience Built for macOS
At a glance
- What is it?
- ClashMac is a proprietary macOS proxy front end built in SwiftUI around a mihomo-style kernel, with a visual route map, connection rules and a fingerprint browser mode. It is a binary download, not a package, and the repository holds no source.
- Who is it for?
- Adopt ClashMac if you run macOS 15 or later, want a menu bar Clash-style client without editing YAML by hand, and accept that the app is proprietary and that the only reviewable code is the third-party licence list. Do not adopt it if you need source auditing, a Linux or Windows client, or a package-manager install.
- Can I use it commercially?
- Check first. The repository uses a licence we do not classify automatically, so read its LICENSE file before any commercial use.
- Is it still maintained?
- Yes. The repository last received commits 2 days ago.
- What is it written in?
- GitHub does not report a main language for this repository.
Answers come from the project's GitHub data, last synced on September 30, 2026, and from our analysis. They are not legal advice.
Editorial analysis
What ClashMac 27 is, and the macOS 15 wall in front of it
ClashMac is a proxy client for macOS built around a Clash/mihomo-style core. The README describes it as a native proxy experience built for macOS, written in SwiftUI, and lists the topics clash, clash-meta, macos, mihomo, network, proxy and swiftui. The interface is a menu bar app with a dashboard, a route map, a topology view and a connection list.
The audience is narrow by design. The README states the system requirement as macOS 15.0+ (Sequoia or later), so anyone on macOS 14 or older is out before they start. Within that group the target reader is someone who wants TUN-based system-wide proxying and per-app routing rules but does not want to hand-write a configuration file. The repository itself contains no source code: the top-level entries are .github/, .gitignore, LICENSE, README.md, THIRD_PARTY_LICENSES.txt and assets/. The README says plainly that ClashMac is proprietary, closed-source software and that binary releases are provided in the repository. That single sentence should shape how you evaluate everything else on this page.
The kernel, the helper tool and the traffic path
The architecture the README implies has three parts. A SwiftUI front end draws the dashboard, route map and connection grid. A separate kernel engine does the proxying; on first launch ClashMac registers its system helper tool and downloads the kernel build matching the Mac's CPU architecture, Apple Silicon or Intel. The helper is the privileged component that installs the network service and owns TUN, described as system-wide proxy integration with complete UDP and TCP capture.
The README adds a security boundary around that helper: it is hardened and restricted to run core files solely from /Applications/ClashMac.app/. That is a real constraint rather than a marketing line, because it means the kernel binary has to live inside the app bundle. It also explains the installer warning. The README cautions against running ClashMac directly from the .dmg window, because the macOS security sandbox will prevent the application from saving settings and installing system network services. Drag the app to Applications first, then launch it.
Data flow for the visible features is local. The route map updates every 10 seconds according to the README, and the dashboard keeps a 60-second window of upload and download bandwidth. The README also claims a smart obfuscation option that randomizes the departure point across 190+ global cities. Read that as a display-layer feature: it changes what the map shows, and the README does not claim it changes the actual exit node.
Installing ClashMac from the DMG and clearing Gatekeeper
There is no Homebrew formula and no package manager step in the README. Installation is a manual download from the Releases page. The file to look for is ClashMac.dmg, attached to the latest release; the repository's most recent tags at the time of writing are 27.1.6 and 27.1.5, with a separate Prerelease-Alpha build.
Once the app is in Applications, first launch is not a normal double-click. The README instructs you to right-click ClashMac.app and choose Open. On that first run ClashMac registers its helper tool and downloads the matching kernel engine for your CPU architecture.
If macOS refuses to launch it with a developer-cannot-be-verified warning, the README gives two routes. The first is System Settings, then Privacy & Security, then Open Anyway on the block notice. The second is a Terminal command that strips the quarantine attribute:
sudo xattr -rd com.apple.quarantine /Applications/ClashMac.appThe README does not document what happens if you run that command before moving the app out of the .dmg, and it does not describe an uninstall procedure for the helper tool. Those are gaps, not features. After the helper is authorized once, the README says you will not be prompted for admin passwords again for routine operation.
The fingerprint browser mode and the cm fp CLI
The most distinctive part of ClashMac is not the proxy dashboard. It is the anti-detect fingerprint browser bundled into the same app. The README describes profiles that align browser timezone, language, locale and User-Agent with the active proxy node, plus multi-profile isolation with separate cookies, cache and proxy endpoints. A shared extension center installs a Chrome extension once by Web Store URL or ID and makes it available across profiles.
Automation runs through a command-line tool named cm fp. The README lists what it covers: automating browser workflows, capturing full-page screenshots, evaluating scripts and extracting cookies. The README does not publish the subcommand syntax beyond the cm fp prefix, so treat the CLI as documented by name only. If scripted extraction is central to your workflow, that gap matters more than the feature list does.
This mode is also where the product stops being a proxy client. Fingerprint browsers are used for multi-account operation and scraping, and pairing one with a proxy switcher puts both capabilities behind a single binary you cannot inspect. The README's privacy section says all settings, traffic details and history stay locally on the Mac, with no data collection, tracking or logs. That is a statement about the vendor's servers, not about what a fingerprint profile does to the sites you visit with it.
Where ClashMac is the wrong tool
The first limitation is the licence. ClashMac is proprietary and closed source. You cannot read the networking code, you cannot build it yourself, and you cannot patch a routing bug. For a component that installs a privileged helper and captures all UDP and TCP traffic, that is the central trade-off of the project, and the README does not pretend otherwise. The only reviewable artefact in the repository is THIRD_PARTY_LICENSES.txt.
The second is platform lock. macOS 15.0 or later, and nothing else. No Linux, no Windows, no older Macs. If your team runs mixed hardware, ClashMac covers only part of it.
The third is distribution. Every update is a DMG you download and drag, with a Gatekeeper warning to clear and a helper tool that may need re-authorizing. There is no documented auto-update channel in the README and no rollback instructions, so if a release regresses your routing you are reinstalling an older DMG by hand.
Finally, the README does not document configuration import. Clash-family clients are usually judged on how faithfully they run an existing subscription or YAML profile; the README here talks about one-click rules for the active tab or process, not about importing a provider file. If you already maintain a large Clash configuration, verify import behaviour before you commit.
ClashMac against Clash Verge and ClashX
The obvious alternatives are the open source Clash front ends, Clash Verge and ClashX, both of which appear in what people search for alongside this project. The difference is not the kernel. All three sit on top of a mihomo-style core, and Mihomo itself is a separate open source project with its own repository.
The difference is the layer above. Clash Verge and ClashX are open source, so the configuration handling, the update mechanism and the privileged-helper code are all readable, and their releases are typically installable through package managers or at least verifiable builds. ClashMac trades that away for a SwiftUI interface, a route map, a topology view and the fingerprint browser mode. If your reason for choosing ClashMac is the visual dashboard or the multi-profile browser, the closed source is the price. If your reason is simply that you want Clash on a Mac, the open source front ends give you the same kernel with a reviewable wrapper.
Surge is the other comparison worth naming, since it also appears in related searches. It is a commercial macOS proxy client with its own rule syntax rather than a Clash-compatible one. Moving between Surge and ClashMac means rewriting rules, not just re-importing them.
Maintenance cadence, updates and what the licence means for you
The repository is not archived, and the last push was on 2026-09-21, the same day as the 27.1.6 release. Release 27.1.5 landed on 2026-09-20, and a Prerelease-Alpha build was pushed on 2026-09-21. That is a fast cadence, and it cuts both ways: fixes arrive quickly, and so do regressions, on a channel where you install by hand.
The licence field on the repository reads NOASSERTION, and the README states the software is proprietary and closed source. Practically, that means the LICENSE file in the repository governs redistribution of the binaries, not your rights to the code, because there is no code to license. Before you ship ClashMac inside an organisation, read that file and THIRD_PARTY_LICENSES.txt rather than assuming the project is open source because it is hosted on GitHub. This is not legal advice; it is a pointer to the two files that answer the question.
The upgrade cost is operational. Each version is a DMG drag, a possible Gatekeeper prompt, and a kernel engine that may be re-downloaded for your architecture. Budget for that if you manage more than a couple of Macs. The README documents no silent update path, so there is nothing to configure and nothing to pin.
Editorial conclusion
Adopt ClashMac if you run macOS 15 or later, want a menu bar Clash-style client without editing YAML by hand, and accept that the app is proprietary and that the only reviewable code is the third-party licence list. Do not adopt it if you need source auditing, a Linux or Windows client, or a package-manager install. Verify first that the release you download is the ClashMac.dmg attached to the latest GitHub release, that your Mac meets the macOS 15.0+ requirement, and that you are comfortable granting the helper tool the network privileges it asks for on first launch.
Frequently asked questions
What is ClashMac?
ClashMac is a proprietary macOS proxy client built in SwiftUI around a Clash/mihomo-style kernel. It combines a menu bar dashboard, a live route map, per-app connection rules and an anti-detect fingerprint browser mode in one app.
How do I install ClashMac?
Download the latest ClashMac.dmg from the Releases page, drag ClashMac.app into your Applications folder, then right-click the app and choose Open on first launch so it can register its helper tool and download the kernel engine matching your CPU architecture.
Is ClashMac open source?
No. The README states that ClashMac is proprietary, closed-source software and that the repository provides binary releases. The only reviewable files in the repository are the licence texts, including THIRD_PARTY_LICENSES.txt.
What macOS version does ClashMac require?
The README lists the system requirement as macOS 15.0 or later, meaning Sequoia or newer. Older macOS releases are not supported.
What is the cm fp command in ClashMac?
The README describes cm fp as the command-line tool for the fingerprint browser mode, used to automate browser workflows, capture full-page screenshots, evaluate scripts and extract cookies. The README does not publish the full subcommand syntax.
Official sources
Add this badge to your README
If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.
[](https://hysenlabs.com/projects/666os-clashmac)