Security researchers have discovered a new macOS malware called PamStealer that is designed to quietly steal login passwords and sensitive information from Apple devices. The malware pretends to be the popular Maccy clipboard manager and is distributed through fake websites that closely copy the legitimate application. Researchers at Jamf Threat Labs uncovered the campaign and found that it uses several advanced techniques to avoid detection. The discovery highlights how macOS-focused malware is becoming more sophisticated.

pamstealer-mac-password-stealer-cyberattack

PamStealer works through a two-stage infection process. The first stage is delivered inside a disk image containing a compiled AppleScript file that appears to be part of the Maccy application. When users open the file, they are instructed to press Command + R, which silently runs the hidden malicious code. This method helps the malware execute while avoiding some of macOS’s normal security protections.

Instead of relying on common command-line tools, the malware uses JavaScript for Automation (JXA) together with native Objective-C APIs to download its second-stage payload. Researchers say this creates a much quieter attack chain because it leaves fewer suspicious processes running on the system. The second stage is written in Rust, a language that is still uncommon among macOS information-stealing malware, making the campaign even more notable.

pamstealer-macos-malware-applescript-attack

The malware secretly installs itself by pretending to be trusted macOS components such as Finder or Software Update. It hides inside application folders, copies genuine-looking icons, and launches in the background without showing visible windows. It also adds itself to the user’s login items, allowing it to automatically start every time the Mac is turned on while remaining difficult for users to notice.

One of PamStealer’s most unique features is the way it steals passwords. Instead of immediately sending every password entered by the victim, it first checks whether the password is correct using the Pluggable Authentication Modules (PAM) interface built into macOS. This local verification allows the malware to confirm it has captured the right login password before transmitting it to the attackers, reducing unnecessary activity that security tools might detect.

login-credential-theft-password-phishing-attack

To trick users, the malware displays a password prompt that looks almost identical to a genuine macOS authorization request. The message claims that Maccy needs permission to make changes and asks for the user’s login password. If the wrong password is entered, the prompt simply appears again until the correct one is provided. After successfully collecting the password, the malware displays a fake error message saying the application is damaged, making the failed installation appear harmless.

Researchers also found that PamStealer is capable of collecting browser data and requesting Full Disk Access, which could allow attackers to gather even more sensitive information from the infected Mac. Analysis of the malware also uncovered code related to cryptocurrency activity, including references to Ethereum infrastructure. These findings suggest the malware may target cryptocurrency-related data in addition to login credentials.

ethereum-cryptocurrency-malware-data-theft

Jamf Threat Labs said PamStealer shows how macOS malware continues to evolve by combining trusted-looking applications, stealthy execution methods, native system features, and advanced credential theft techniques. The researchers advise Mac users to download software only from trusted sources, carefully verify website addresses before installing applications, and remain cautious of unexpected password prompts, even when they appear to come from legitimate macOS software.

Stay alert, and keep your security measures updated!

Source: Follow cybersecurity88 on X and LinkedIn for the latest cybersecurity news