Malware · 60 days ago
Signed Mac Malware Turns Trust Into the Bypass macOS trust checks are doing the attacker’s job here. A signed, notarized installer can get past Gatekeeper, then the stealer goes after the account data people actually use to log in, approve transactions, and unlock systems.
Jamf and Thijs Xhaflaire identified CrashStealer as a native C++ macOS information stealer delivered through a notarized disk image and valid developer ID. It validates the victim’s password locally, then collects browser data, cryptocurrency wallets, password managers, files, and keychain material, and it can copy and re-sign itself to persist. The reporting also ties the operation to shared backend infrastructure and other domains, pointing to a broader multi-platform campaign.
Timeline Sources 5 sources covering this story
SecurityWeek Jul 16
‘ClickLock Stealer’ Bypasses macOS Security With Social Engineering, Process Killing
The new macOS malware has targeted at least 100 users to steal their passwords and cryptocurrency.
Help Net Security Jul 14
New macOS malware steals passwords by posing as Apple's crash-reporting tool - Help Net Security
Jamf Threat Labs has uncovered a new macOS infostealer named CrashStealer that disguises itself as Apple's crash-reporting tool.
Infosecurity Magazine Jul 14
New MacOS Malware Exploits Legitimate Developer ID
Researchers at Jamf Threat Labs detail CrashStealer, which steals passwords, cryptocurrency wallets and more
The Hacker News Jul 13
CrashStealer macOS Malware Uses Notarized Dropper to Pass Gatekeeper Checks
CrashStealer uses a notarized macOS dropper to pass Gatekeeper, then steals browser, wallet, password manager, file, and keychain data.
BleepingComputer Jul 13
New CrashStealer malware poses as Apple crash reporting tool
A new macOS information-stealing malware called CrashStealer pretends to be Apple's crash-reporting tool to steal credentials, keychain data, and crypto wallets.
Part of the PlainSec briefing for 2026-07-17
Editions Related stories
Malware · 60 days ago
Signed Mac Malware Turns Trust Into the Bypass macOS trust checks are doing the attacker’s job here. A signed, notarized installer can get past Gatekeeper, then the stealer goes after the account data people actually use to log in, approve transactions, and unlock systems.
Jamf and Thijs Xhaflaire identified CrashStealer as a native C++ macOS information stealer delivered through a notarized disk image and valid developer ID. It validates the victim’s password locally, then collects browser data, cryptocurrency wallets, password managers, files, and keychain material, and it can copy and re-sign itself to persist. The reporting also ties the operation to shared backend infrastructure and other domains, pointing to a broader multi-platform campaign.
Timeline Sources 5 sources covering this story
SecurityWeek Jul 16
‘ClickLock Stealer’ Bypasses macOS Security With Social Engineering, Process Killing
The new macOS malware has targeted at least 100 users to steal their passwords and cryptocurrency.
Help Net Security Jul 14
New macOS malware steals passwords by posing as Apple's crash-reporting tool - Help Net Security
Jamf Threat Labs has uncovered a new macOS infostealer named CrashStealer that disguises itself as Apple's crash-reporting tool.
Infosecurity Magazine Jul 14
New MacOS Malware Exploits Legitimate Developer ID
Researchers at Jamf Threat Labs detail CrashStealer, which steals passwords, cryptocurrency wallets and more
The Hacker News Jul 13
CrashStealer macOS Malware Uses Notarized Dropper to Pass Gatekeeper Checks
CrashStealer uses a notarized macOS dropper to pass Gatekeeper, then steals browser, wallet, password manager, file, and keychain data.
BleepingComputer Jul 13
New CrashStealer malware poses as Apple crash reporting tool
A new macOS information-stealing malware called CrashStealer pretends to be Apple's crash-reporting tool to steal credentials, keychain data, and crypto wallets.
Part of the PlainSec briefing for 2026-07-17
Editions Related stories