Malware & Tooling · Credential Theft
Signed Mac Malware Turns Trust Into the Bypass macOS trust checks are doing the attacker’s job here. A signed, notarized installer can get past Gatekeeper, then the stealer goes after the account data people actually use to log in, approve transactions, and unlock systems.
Jamf and Thijs Xhaflaire identified CrashStealer as a native C++ macOS information stealer delivered through a notarized disk image and valid developer ID. It validates the victim’s password locally, then collects browser data, cryptocurrency wallets, password managers, files, and keychain material, and it can copy and re-sign itself to persist. The reporting also ties the operation to shared backend infrastructure and other domains, pointing to a broader multi-platform campaign.
5 sources · Jul 16
Timeline Sources Jul 16 SecurityWeek
‘ClickLock Stealer’ Bypasses macOS Security With Social Engineering, Process Killing
The new macOS malware has targeted at least 100 users to steal their passwords and cryptocurrency.
original Jul 14 Help Net Security
New macOS malware steals passwords by posing as Apple's crash-reporting tool - Help Net Security
Jamf Threat Labs has uncovered a new macOS infostealer named CrashStealer that disguises itself as Apple's crash-reporting tool.
original Jul 14 Infosecurity Magazine
New MacOS Malware Exploits Legitimate Developer ID
Researchers at Jamf Threat Labs detail CrashStealer, which steals passwords, cryptocurrency wallets and more
original Part of the PlainSec briefing for 2026-07-13
Every edition of this story: Signed Mac Malware Turns Trust Into the Bypass
More from today
Malware & Tooling · Credential Theft
Signed Mac Malware Turns Trust Into the Bypass macOS trust checks are doing the attacker’s job here. A signed, notarized installer can get past Gatekeeper, then the stealer goes after the account data people actually use to log in, approve transactions, and unlock systems.
Jamf and Thijs Xhaflaire identified CrashStealer as a native C++ macOS information stealer delivered through a notarized disk image and valid developer ID. It validates the victim’s password locally, then collects browser data, cryptocurrency wallets, password managers, files, and keychain material, and it can copy and re-sign itself to persist. The reporting also ties the operation to shared backend infrastructure and other domains, pointing to a broader multi-platform campaign.
5 sources · Jul 16
Timeline Sources Jul 16 SecurityWeek
‘ClickLock Stealer’ Bypasses macOS Security With Social Engineering, Process Killing
The new macOS malware has targeted at least 100 users to steal their passwords and cryptocurrency.
original Jul 14 Help Net Security
New macOS malware steals passwords by posing as Apple's crash-reporting tool - Help Net Security
Jamf Threat Labs has uncovered a new macOS infostealer named CrashStealer that disguises itself as Apple's crash-reporting tool.
original Jul 14 Infosecurity Magazine
New MacOS Malware Exploits Legitimate Developer ID
Researchers at Jamf Threat Labs detail CrashStealer, which steals passwords, cryptocurrency wallets and more
original Part of the PlainSec briefing for 2026-07-13
Every edition of this story: Signed Mac Malware Turns Trust Into the Bypass
More from today