💛 A quick favor, if you've got a second.
We're really happy that you chose to read one of our stories and sincerely hope you'll stick around to read more. We took our paywall down — for now — but that won't last forever, and when the gate goes back up, we'd love for you to already be on the inside.
It's free. So please enter your email here and don't forget to like and follow us on all of your favorite Social Media platforms!

Jamf Threat Labs has identified CrashStealer, a newly developed Mac information stealer designed to deceive users by mimicking Apple’s official crash-reporting application. The malware first appeared under development in May 2026, with active attacks detected by early July. Unlike many Mac-based credential theft tools, CrashStealer was written in native C++, providing attackers with greater sophistication and evasion capabilities.
The malware targets a broad range of sensitive data stored on compromised devices. Its theft targets include browser credentials, password manager databases, cryptocurrency wallet information and Mac login Keychain files. The stolen data is encrypted using AES-256-GCM before being transmitted to attacker-controlled servers, and the malware employs anti-debugging features to complicate analysis by security researchers.
The attack chain begins with a disk image labeled “Werkbit Setup,” which contains a professionally designed installer. The initial installer carries a valid Apple Developer ID and notarization ticket, allowing it to bypass Gatekeeper security protections on first launch. The distribution website required users to provide a meeting PIN, a tactic that limited access to intended victims and enhanced the campaign’s credibility.
Once executed, the Werkbit installer contacts GitHub for initial commands and downloads a script from the attackers’ infrastructure. This script deploys a second disk image named CrashReporter.dmg into a hidden temporary folder, using naming conventions and bundle identifiers designed to resemble legitimate Apple system components. The payload then launches silently in the background without user awareness.
CrashStealer displays a password prompt designed to mimic legitimate macOS authorization requests. When users enter their credentials, the malware validates the password locally using built-in Mac directory service commands. If correct, it stores an obfuscated copy and uses the credential to unlock the login Keychain, gaining access to all stored passwords and sensitive data.
The malware searches extensively across infected systems for valuable information. Jamf discovered code targeting Chromium-based browsers, Safari data and Firefox credential files, along with approximately 80 cryptocurrency wallet extensions including MetaMask and Phantom. Password managers in the theft list include 1Password, Bitwarden, LastPass and Dashlane, totaling 14 targeted applications.
Stolen materials are stored in hidden folders within the user’s home directory, with each collected item encrypted before being packaged into hidden ZIP archives for upload. The malware then copies itself into the Mac’s Library cache folder and creates a LaunchAgent using Apple-like naming conventions to persist across system restarts and user logins.
Users should download software exclusively from the Mac App Store or by typing official website addresses directly into their browser. Suspicious requests to override security warnings, unexpected password prompts immediately after installation and unfamiliar applications requesting Full Disk Access represent critical warning signs. Regular review of System Settings for unrecognized apps and permissions provides an additional protective measure.
Users who suspect infection should immediately disconnect the affected Mac from the internet and refrain from entering additional passwords. A full scan using trusted security software should be conducted, followed by password changes for all critical accounts on a separate clean device. Cryptocurrency wallet users should treat private keys and recovery phrases as potentially compromised and transfer remaining funds to newly created wallets established from uninfected devices.
More Stories
Packers Running Back Josh Jacobs Placed on NFL Commissioner’s Exempt List Following Domestic Arrest
Federal Prosecutors Convene Special Grand Jury to Investigate D.C. Schools’ Attendance and Graduation Practices
Denver Broncos Linebacker Jonathon Cooper Placed on Commissioner’s Exempt List Amid Domestic Violence Charges