July 29, 2026
Tech

New CrashStealer Mac Malware Targets Passwords and Cryptocurrency Wallets

Security researchers have identified CrashStealer, a sophisticated new macOS information stealer that mimics Apple's crash reporting system to pilfer sensitive user data.

July 21, 2026

New CrashStealer Mac Malware Targets Passwords and Cryptocurrency Wallets

A meticulously crafted installer can make potentially malicious software appear legitimate. Users may encounter a familiar Mac interface, follow installation prompts, and enter their password when requested. By this point, however, the application may already be compromising their system.

Security experts at Jamf Threat Labs have uncovered CrashStealer, a novel information-stealing malware designed for macOS. This sophisticated threat masquerades as Apple's native crash-reporting software. Jamf began monitoring the malware's development in May 2026, observing it in active attacks by early July.

How CrashStealer Operates

CrashStealer is designed to extract highly sensitive information that many individuals rely on daily. It actively searches for browser credentials, data from password managers, and cryptocurrency wallet details. The malware is also capable of copying the Mac login Keychain. What distinguishes CrashStealer is its development in native C++, a departure from many common Mac stealers that often utilize AppleScript or simpler software wrappers.

The malware further enhances its stealth by encrypting all collected files before transmitting them to a server controlled by the attackers. Additionally, anti-debugging functionalities are incorporated, making it more challenging for security researchers to analyze. The initial application encountered by a victim is not named CrashStealer; the attack commences with a disk image branded as "Werkbit Setup."

The "Werkbit Setup" disk image contains a professionally designed installer. Its instructions guide the user to right-click the application and select "Open." This particular instruction is frequently seen with software that needs to bypass a Mac security warning. However, in this instance, the installer already possessed a valid Apple Developer ID and a notarization ticket, allowing it to clear Gatekeeper upon its initial launch. Jamf also noted that the disk image itself was signed, a characteristic that researchers deemed unusual for malicious Mac delivery methods.

The website from which "Werkbit Setup" was distributed required a meeting PIN. This requirement likely helped the attackers restrict access to individuals who possessed the correct code, while also making the download seem more exclusive and potentially more credible.

Upon execution, "Werkbit Setup" established contact with GitHub for an initial command. It then downloaded a script from the attackers' infrastructure. Subsequently, this script installed a second disk image, named CrashReporter.dmg, into a hidden temporary folder. The malicious payload adopted the name "CrashReporter" and the bundle identifier "com.apple.crashreporter" to closely resemble an authentic Apple system component. The malware then launched discreetly in the background.

Apple implements Gatekeeper alongside Developer ID signing to mitigate risks from downloaded software. Its notarization process scans an application for known malicious content when developers submit it. Gatekeeper can also verify if Apple has revoked a signing certificate. Nevertheless, a notarized label should not override a user's careful judgment regarding an application's origin.

A malicious application can sometimes evade detection before security researchers or Apple identify its harmful behavior. Attackers may also employ a trusted first-stage installer to retrieve a different, more dangerous payload after the initial launch. Jamf reported the Developer Team ID associated with "Werkbit Setup" to Apple after confirming its role in distributing malicious software. The report did not specify the number of individuals who might have been affected.

Identifying a Potential Infection

After CrashStealer is launched, it presents a password prompt crafted to mimic a legitimate macOS authorization request. The malware locally verifies the entered password using a built-in Mac directory service command.

If an incorrect password is provided, the prompt reappears. If the correct password is entered, CrashStealer stores an obfuscated copy and utilizes the credential to unlock the login Keychain.

The malware can then copy the Keychain database into its collection folder. Consequently, this password prompt serves as one of the most critical warning signs. While the request may appear convincing, its timing might feel inappropriate. An installer for an online meeting, for example, should not require your Mac password to display a call or download standard content.

CrashStealer conducts an extensive search across the Mac system. Jamf identified code and activity targeting Chromium-based browsers, Safari data, and Firefox credential files. The malware also checked for wallet extensions like MetaMask and Phantom. Furthermore, it targeted password managers including 1Password, Bitwarden, LastPass, and Dashlane. Jamf observed approximately 80 cryptocurrency wallet extensions and 14 password managers on the malware's target list.

A separate file-scanning utility examines locations such as Documents and Downloads. However, it specifically bypasses many large installers, applications, and media files. This filtering suggests that the attackers are interested in smaller, more compact files that may contain credentials or financial records. Other personal documents could also be of interest to the perpetrators.

CrashStealer stores stolen materials within hidden folders located under the user's home directory. Each collected item is encrypted using AES-256-GCM. Subsequently, groups of encrypted files are packaged into hidden ZIP archives before being uploaded. This encryption helps attackers conceal the contents of the stolen files while they reside on the Mac. It also means that a leftover archive can confirm that data collection occurred, even if an investigator cannot read the data within it.

The malware then creates a copy of itself in the Mac's Library cache folder. It establishes a LaunchAgent that initiates the copied application whenever the user logs in. The LaunchAgent uses an Apple-like name, which can help the entry blend in during a quick system inspection.

You may have encountered this campaign after downloading "Werkbit Setup." The risk increases if the associated website demanded a meeting PIN. An unexpected password prompt from "CrashReporter" is another significant red flag. Exercise greater suspicion if such a prompt appears immediately after installing unrelated software or joining an online meeting.

Additionally, be alert for any unfamiliar application requesting Full Disk Access or permission to access Documents and Downloads. CrashStealer's configuration included permission messages designed to make broad file access seem necessary for "system administration." Security teams can also look for the hidden CrashReporter locations and LaunchAgent detailed in Jamf's technical report. However, most home users should avoid manually searching through system folders unless they possess a clear understanding of the changes they are making.

Protecting Your Mac from Information Stealers

Adopting a few careful habits can help you detect a suspicious Mac installer before it gains access to your passwords and personal files:

  • When possible, use the Mac App Store. Otherwise, manually type the developer's official website address. Avoid downloading software from a meeting link, private message, or unexpected pop-up unless you can independently verify the source.
  • Be cautious if an installer instructs you to right-click and choose "Open" or use the "Open Anyway" button. Apple advises overriding a security warning only when you explicitly trust the application's source. You should also confirm that the downloaded file has not been tampered with.
  • Examine which application is triggering a password prompt and determine why it requires authorization. Cancel the request if the reason does not align with your current activity. Then, close the application and independently verify the download with the company through a separate communication channel.
  • Access the Apple menu > System Settings > Privacy & Security. Review Full Disk Access, Files & Folders, and Accessibility for any applications you do not recognize. Disable access for anything suspicious.
  • Next, navigate to System Settings > General > Login Items & Extensions. Review the applications listed under "Open at Login" and "Allow in the Background." Remove or disable any unfamiliar entries.
  • You can also check System Settings > General > Device Management for profiles you do not recognize. This option might only appear if a profile is installed. Do not remove a work or school profile without first contacting the administrator.
  • Open the Apple menu > System Settings > General > Software Update. Install available updates promptly, as they include critical security protections.
  • A reputable antivirus program can help detect known malicious files, suspicious persistence mechanisms, and harmful network behavior. Keep real-time protection enabled and allow the software to update automatically. Jamf states that threat-prevention tools can assist in blocking and reporting similar Mac threats.

If You Suspect an Infection

  • Immediately disconnect your Mac from the internet. Do not enter any further passwords on that computer.
  • Run a full scan with trusted security software.
  • Contact Apple Support or your workplace IT team for assistance.
  • Using a clean, separate device, change the password for your Apple Account, primary email account, and password manager. Update passwords for banking, shopping, and any other sensitive accounts that were saved on the affected Mac. Enable two-factor authentication (2FA) wherever available and sign out of any unrecognized devices or active sessions.
  • After your Mac has been thoroughly cleaned, change its login password, as CrashStealer may have captured and validated that credential.
  • If you use cryptocurrency wallets on the compromised Mac, consider their private keys and recovery phrases exposed. Move any remaining funds to newly created wallets from a clean device. Never reuse the old recovery phrase.
  • If security software cannot definitively confirm that CrashStealer has been fully removed, contact Apple Support or a qualified technician about erasing your Mac and reinstalling macOS. Carefully restore personal files from a backup created prior to the infection, if possible.

CrashStealer exemplifies how attackers can package malicious software within a highly convincing Mac user experience. The signed "Werkbit" installer provided the campaign with a layer of credibility. Subsequently, the deceptive crash reporter utilized a familiar password prompt to access valuable data on the computer. Your primary defense begins before any password prompt appears: always verify the source of every installer and halt the process if instructions request you to bypass a security warning. Robust antivirus protection and up-to-date macOS software provide an additional layer of security.

CrashStealerMac malwaremacOS securitypassword stealercryptocurrency wallet securityJamf Threat Labsinformation stealerApple Gatekeeper

More Stories