macOS trust checks are doing the attacker’s job here. A signed, notarized installer can get past Gatekeeper, then the stealer goes after the account data people actually use to log in, approve transactions, and unlock systems.
Jamf and Thijs Xhaflaire identified CrashStealer as a native C++ macOS information stealer delivered through a notarized disk image and valid developer ID. It validates the victim’s password locally, then collects browser data, cryptocurrency wallets, password managers, files, and keychain material, and it can copy and re-sign itself to persist. The reporting also ties the operation to shared backend infrastructure and other domains, pointing to a broader multi-platform campaign.