All incidents

CrashStealer macOS infostealer discovered by Jamf Threat Labs

malwareclosedJul 14, 2026 — Jul 19, 2026
CrashStealer macOS infostealer discovered by Jamf Threat Labs

JAMF Threat Labs has uncovered a new macOS infostealer dubbed CrashStealer that disguises itself as a legitimate crash‑reporting tool to harvest credentials and cryptocurrency wallet data according to its analysis. The malware was first seen in May 2026 and observed in active deployment through mid‑July 2026.

CrashStealer is written in C++ and is distributed inside a signed disk image that contains a malicious application named Werkbit.app which leverages a valid Developer ID to slip past Gatekeeper. After execution it contacts a GitHub repository, downloads a Base64‑encoded shell script and runs it to deploy the main payload as detailed in further research.

The infostealer targets data from Safari, Chrome and Firefox as well as popular cryptocurrency wallets such as MetaMask and phantom. Collected information is encrypted with AES‑256‑GCM before being exfiltrated to a command‑and‑control server. To stay hidden CrashStealer installs a LaunchAgent for persistence and employs anti‑analysis checks that abort execution if a debugger or virtual environment is detected.

Although no specific threat actor has been linked to the campaign, the malware has been seen in the wild affecting users across several regions. Its use of a signed application to bypass built‑in macOS defences illustrates a growing trend of abusing trusted code‑signing mechanisms. Researchers note that the timing of the activity coincides with an increase in macOS‑focused infostealer offerings on underground forums as highlighted in a recent malware newsletter.

Organisations should enforce strict Gatekeeper policies that block execution of apps from unidentified developers unless explicitly approved. Security teams ought to monitor LaunchAgents and LaunchDaemons for unfamiliar entries and inspect any signed disk images that appear in user download folders. Network monitoring should flag outbound connections to GitHub URLs that deliver Base64‑encoded scripts, especially when followed by TLS traffic to unknown endpoints.

Endpoint detection rules can be tuned to recognise the AES‑GCM encryption routine used by CrashStealer, which often appears as a series of AES‑NI instructions coupled with a specific nonce pattern. Users need to be educated about unexpected password prompts that mimic legitimate macOS authorization dialogs, as these are a common social‑engineering lure. Finally, keeping macOS and third‑party browsers up to date reduces the amount of valuable data that stealer can harvest.

Intelligence briefing updated Jul 19, 2026

Root sourcewww.jamf.com
Timeline Coverage

Swipe to explore timeline