< Back to all clusters
[TECHNOLOGY] · Belgium, Italy, Czechia, Germany, Türkiye · 14 sources

CrashStealer macOS malware tricks users and steals passwords, crypto

CrashStealer is a macOS information‑stealer that disguises itself as Apple’s built‑in CrashReporter utility. The malware is delivered in a fake app called Werkbit that carried a valid developer ID and a notarization stamp, allowing it to bypass macOS Gatekeeper and appear legitimate. When launched it shows a native‑looking password prompt; the entered password unlocks the user’s Keychain, giving the malware access to saved credentials, Wi‑Fi passwords, and other secrets.

The code then harvests data from browsers, 14 password‑manager applications (including 1Password, LastPass and Dashlane), and more than 80 cryptocurrency‑wallet extensions. Collected information is encrypted with AES‑256‑GCM via Apple’s CommonCrypto and transmitted to a command‑and‑control server. Jamf Threat Labs first spotted the strain in May 2026; active campaigns were observed in July 2026, with distribution gated behind a PIN, suggesting a targeted rather than mass campaign. Apple has revoked the developer certificate used for the Werkbit installer, but researchers warn that the technique could be reused with other signed packages.

The threat highlights that notarization and signature alone no longer guarantee safety, and users should be wary of any macOS app that asks for a system password immediately after launch, especially if it mimics a native Apple tool.

Sources