Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: pamstealer (2 articles)Clear

PamStealer macOS malware adds server-side decryption and fake crypto wallet lure

Jamf Threat Labs flagged a new version of the PamStealer macOS infostealer that can only be unpacked with the attacker's server. Earlier variants embedded payload key material directly in the JavaScript for Automation dropper, but the latest completes a key exchange with the server before the payload unwraps, so it cannot be recovered from a static sample alone. The lure also changed: where July and August versions impersonated the Maccy, Scoppr, and Nancy Clipboard apps, victims are now drawn to a fake site advertising a non-existent cryptocurrency wallet called Wavel. Clicking Download for macOS retrieves a disk image whose AppleScript opens Script Editor with instructions to run the dropper.

Check
Warn macOS users against installing apps from search-driven download sites, and alert on AppleScript files opening Script Editor and JXA droppers reaching external servers.
Affected
macOS users lured by the fake Wavel crypto wallet site run a JXA dropper that fetches a server-side decrypted stealer payload with layered persistence.
Fix
Restrict installation to trusted sources, monitor for JXA and osascript activity contacting unknown hosts, and educate users on fake wallet and app lures.

PamStealer Mac malware poses as a clipboard app and verifies passwords through PAM

Jamf Threat Labs found a new macOS infostealer, PamStealer, that impersonates Maccy, a popular open-source clipboard manager, through a fake website. Victims download what looks like a Maccy installer but is a malicious AppleScript that quietly fetches a Rust-based stealer. Its standout trick is how it grabs the login password: it shows a native-looking prompt saying "Maccy wants to make changes" and validates whatever the user types against macOS's own Pluggable Authentication Modules, so it only keeps a confirmed-correct password and avoids the noisy process calls other stealers make. The second stage hides as Finder, encrypts its traffic, and delays its Full Disk Access request to avoid suspicion.

Check
Make sure anyone using the Maccy clipboard manager downloaded it only from maccy.app or its official GitHub, and treat unexpected admin-password prompts and Full Disk Access requests during app installs with suspicion.
Affected
Mac users who install software from fake or unofficial sites; PamStealer poses as the Maccy clipboard app, confirms the login password through macOS PAM, then steals credentials, browser data, and wallet access.
Fix
Install Mac apps only from official sites or the App Store, verify download URLs carefully, deny unexpected password and Full Disk Access prompts, and keep macOS and endpoint tools updated.