← All articles

PamStealer macOS malware adds server-side decryption and fake crypto wallet lure

Jamf Threat Labs flagged a new version of the PamStealer macOS infostealer that can only be unpacked with the attacker's server. Earlier variants embedded payload key material directly in the JavaScript for Automation dropper, but the latest completes a key exchange with the server before the payload unwraps, so it cannot be recovered from a static sample alone. The lure also changed: where July and August versions impersonated the Maccy, Scoppr, and Nancy Clipboard apps, victims are now drawn to a fake site advertising a non-existent cryptocurrency wallet called Wavel. Clicking Download for macOS retrieves a disk image whose AppleScript opens Script Editor with instructions to run the dropper.

Check
Warn macOS users against installing apps from search-driven download sites, and alert on AppleScript files opening Script Editor and JXA droppers reaching external servers.
Affected
macOS users lured by the fake Wavel crypto wallet site run a JXA dropper that fetches a server-side decrypted stealer payload with layered persistence.
Fix
Restrict installation to trusted sources, monitor for JXA and osascript activity contacting unknown hosts, and educate users on fake wallet and app lures.