Updated
Updated · Fox News · Jul 21
Jamf Uncovers CrashStealer Mac Malware Targeting 80 Wallet Extensions and 14 Password Managers
Updated
Updated · Fox News · Jul 21

Jamf Uncovers CrashStealer Mac Malware Targeting 80 Wallet Extensions and 14 Password Managers

2 articles · Updated · Fox News · Jul 21

Summary

  • Active attacks detected in early July led Jamf Threat Labs to detail CrashStealer, a new Mac infostealer that masquerades as Apple’s Crash Reporter and steals credentials, Keychain data and crypto-wallet information.
  • A signed and notarized first-stage installer called Werkbit Setup helped the campaign clear Gatekeeper, then fetched a hidden CrashReporter.dmg payload that used the bundle identifier com.apple.crashreporter.
  • A fake macOS password prompt is central to the theft: if users enter the correct login password, the malware validates it locally, unlocks the login Keychain and copies sensitive data.
  • Jamf said CrashStealer targets Safari, Firefox and Chromium data, about 80 cryptocurrency wallet extensions and 14 password managers, then encrypts stolen files with AES-256-GCM before uploading them.
  • The campaign shows how trusted Apple signing and notarization can be abused before revocation; Jamf reported the Developer Team ID to Apple, but did not say how many users were infected.

Insights

CrashStealer mimics system alerts to steal passwords. How can you tell a real macOS prompt from a fake one?
If malware can carry Apple's official seal of approval, is the Mac's reputation for security now a myth?

80 Crypto Wallets and 14 Password Managers Targeted: Inside the CrashStealer macOS Malware Breach of 2026

Overview

CrashStealer is a new and sophisticated malware targeting macOS users by pretending to be Apple’s crash-reporting tool. It tricks victims into installing a malicious payload that steals sensitive information, especially passwords. Once installed, CrashStealer harvests a wide range of personal and financial data, including credentials from popular browsers and cryptocurrency wallets. This threat highlights that even Apple users are vulnerable to evolving cyberattacks. The discovery of CrashStealer is a strong reminder that relying on macOS alone is not enough for security, and users must stay vigilant against deceptive threats.

...