Malware · 4h ago
Jamf Threat Labs says a new PamStealer variant for macOS now uses a server-side key exchange to unwrap its second-stage payload, and the latest lure points victims to a fake Wavel crypto-wallet site instead of the earlier fake-app pages.
The infection still starts with a JavaScript for Automation (JXA) dropper, but the JXA layer is now just a carrier: it launches a shell script that fetches a decryption utility, completes an X25519 key exchange with the server, and only then stages the payload. Because the server holds the missing key material, static unpacking and signature-based analysis stop at the carrier unless the C2 side cooperates.
For defenders, that shifts the problem from one file to a live exchange and a layered persistence chain. If users install software from web downloads, especially wallet-themed lures, the visible sample may no longer be the part that matters most.
1 source covering this story
PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence
PamStealer now uses live key exchange to block static payload recovery and is delivered through a fake Wavel macOS download.
Part of the PlainSec briefing for 2026-09-25