Signed Mac Malware Turns Trust Into the Bypass

macOS trust checks are doing the attacker’s job here. A signed, notarized installer can get past Gatekeeper, then the stealer goes after the account data people actually use to log in, approve transactions, and unlock systems. Jamf and Thijs Xhaflaire identified CrashStealer as a native C++ macOS information stealer delivered through a notarized disk image and valid developer ID. It validates the victim’s password locally, then collects browser data, cryptocurrency wallets, password managers, files, and keychain material, and it can copy and re-sign itself to persist. The reporting also ties the operation to shared backend infrastructure and other domains, pointing to a broader multi-platform campaign.

Part of the PlainSec briefing for 2026-07-17

Sources