CrashStealer Mac malware steals passwords and wallets
Security researchers at Jamf Threat Labs have identified a new Mac malware strain, dubbed CrashStealer, which disguises itself as Apple's crash-reporting software to trick users into installing it. The malware uses a convincing, familiar-looking installer to get victims to enter their password, granting it the access it needs to steal sensitive information such as passwords and cryptocurrency wallet data. Its discovery matters because it shows attackers continuing to refine social-engineering tactics that exploit users' trust in legitimate-looking Apple system prompts, while also managing to slip past Apple's built-in security protections.
Jamf first detected CrashStealer in May 2026, when it appeared to still be under development, and by early July had observed it being used in live attacks. The malware is notable for its ability to bypass Gatekeeper, the macOS security feature designed to block unverified or malicious software from running, making it a more serious threat than typical impersonation scams.
- New Mac malware CrashStealer poses as Apple's crash-reporter tool.
- It bypasses Gatekeeper security to steal passwords and wallets.
- Jamf tracked it from May 2026; active attacks seen by July.