Malware · 4h ago

PamStealer Moves Payload Decryption Off the Mac

Jamf Threat Labs says a new PamStealer variant for macOS now uses a server-side key exchange to unwrap its second-stage payload, and the latest lure points victims to a fake Wavel crypto-wallet site instead of the earlier fake-app pages.

The infection still starts with a JavaScript for Automation (JXA) dropper, but the JXA layer is now just a carrier: it launches a shell script that fetches a decryption utility, completes an X25519 key exchange with the server, and only then stages the payload. Because the server holds the missing key material, static unpacking and signature-based analysis stop at the carrier unless the C2 side cooperates.

For defenders, that shifts the problem from one file to a live exchange and a layered persistence chain. If users install software from web downloads, especially wallet-themed lures, the visible sample may no longer be the part that matters most.

Timeline

Sources

1 source covering this story

Part of the PlainSec briefing for 2026-09-25

Editions

Related stories