securityonline.info 28 Sept 2026, 08:11 UTC

Fake Crypto Wallet Sites Deliver macOS Stealer and Password Theft

Fake Crypto Wallet Sites Deliver macOS Stealer and Password Theft
CyberSIXT Evidence Panel Source marked as original reporting

JAMF Threat Labs has identified an active campaign distributing PamStealer, a macOS information-stealing malware, through websites impersonating cryptocurrency platforms. The campaign uses a fake multi-chain wallet called Wavel, delivered in a malicious DMG file containing a compiled AppleScript that can appear to be an ordinary document because macOS hides file extensions by default. Opening it launches an embedded JavaScript application, which decodes and runs a shell command before exiting to reduce visible traces.

The malware downloads a utility called pkgunpack, which obtains an encrypted payload through a live elliptic-curve key exchange with an external server. According to Jamf, the core payload cannot be recovered statically without the server’s cooperation. The decrypted application is renamed Finder.app, placed in the user’s support directory and given an ad-hoc signature.

It suppresses macOS notifications while creating a LaunchAgent that runs every 15 seconds, and uses recovery scripts, shell configuration changes and global Git hooks to restore missing components.

The Swift-based payload, internally referred to as MacClient, presents a fake administrator-password prompt and validates entered credentials through macOS Pluggable Authentication Modules. It can steal login Keychains, alter access controls, collect data from profiles belonging to 17 browsers and gather 21 hardware attributes, along with the user’s account photograph. Stolen data is compressed and sent over encrypted HTTP with a unique authorisation token. Attribution remains unconfirmed.

Jamf and researcher LOpsec recommend investigating suspicious scripts, LaunchAgents, Application Support files, shell configuration changes and Git hooks; users should avoid unverified software-download sites.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline