macOS Stealer CrashStealer Poses as Crash Reporter to Target Crypto Wallets
Cybersecurity company Jamf has uncovered CrashStealer, a new type of macOS malware that masquerades as the system's built-in crash-reporting tool to trick users into entering their passwords and granting access to the system keychain. The malware poses a significant threat because it specifically targets as many as 80 types of cryptocurrency wallets as well as browser credentials. It is also the first such malware to be developed using native C++ code, making it harder for traditional antivirus software to detect.
According to a Jamf Threat Labs investigation published in July 2026, researchers spotted signs that the malware was under development as early as May 2026 and found it had entered active deployment by early July. The malware bypassed system defenses using a malicious certificate that had passed Apple's notarization process. Apple revoked the associated developer certificates in mid-July to prevent further harm.
All Coverage
1 original reportsThe Backstory
The history behind this eventPamStealer Poses as macOS Tool to Steal Crypto Wallets
Malware attacks targeting Apple users have recently become frequent on macOS. A new infostealer called PamStealer masquerades as the popular open-source clipboard utility Maccy and uses macOS’s built-in Pluggable Authentication Modules, or PAM, mechanism to verify administrator privileges. It can specifically steal browser credentials and cryptocurrency wallets. Its ability to bypass system safeguards poses a major threat to users’ digital assets.
Jamf Threat Labs disclosed the malware in July 2026. Attackers created the fake website maccyapp[.]com to trick users into downloading it. The software packages an AppleScript that, when users follow instructions to run it in Script Editor, downloads a second-stage payload written in Rust. The payload impersonates system applications such as Finder to evade detection and steal private data in the background.
macOS Stealer Reaper Impersonates Tech Giants and Targets Crypto Wallets
macOS users are increasingly being targeted by information-stealing malware, with attackers often posing as Apple, Microsoft or Google update alerts to lower their guard. Reaper is particularly significant because it both creates a system backdoor and targets cryptocurrency wallets such as MetaMask and Phantom, potentially gaining access to credentials, private keys and control of assets.
A cybersecurity company recently disclosed that Reaper uses a mix of fake Apple, Microsoft and Google software updates to trick macOS users into installing it, after which it collects wallet data and steals assets. Existing reports have not disclosed the organization that discovered it, the exact disclosure date, the number of victims or the value of losses. Users should update software only through official channels.
Fake CleanMyMac Campaign Steals Mac Users’ Crypto Wallet Data and Personal Information
CleanMyMac is a macOS cleanup tool developed by MacPaw. Attackers created an imitation website and used ClickFix social engineering to trick users into pasting commands into Terminal, bypassing Gatekeeper, Apple notarization and XProtect. The threat is particularly serious because leaked recovery phrases could allow attackers to take direct control of wallet assets.
Malwarebytes disclosed on March 6, 2026, that the fake website, cleanmymacos.org, downloads SHub Stealer. The malware steals Apple Keychain contents, browser data and Telegram sessions, and scans for 23 wallet applications. It also tampers with applications including Ledger Live to capture recovery phrases. The report did not disclose the number of victims or the amount of losses.
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.