A sophisticated new malware targeting Mac users, named CrashStealer, has been discovered by security researchers at Jamf Threat Labs. It masquerades as Apple's legitimate crash-reporting software and was first identified in May 2026, with active attacks detected by early July. CrashStealer is designed to extract sensitive information, including browser credentials, password manager data, and cryptocurrency wallet information, and can copy the Mac login Keychain. It uses native C++ programming, encrypts collected files, and employs anti-debugging features.
The malware is distributed through a disk image labeled "Werkbit Setup," which features a polished installer that bypasses Mac security warnings by using a valid Apple Developer ID and notarization ticket. Once opened, it connects to GitHub for commands and downloads a script that installs a second disk image named CrashReporter.dmg, which mimics an Apple system component.
CrashStealer presents a fake password prompt resembling a legitimate macOS request, verifying entered passwords locally. It targets data linked to various browsers and password managers, scanning for approximately 80 cryptocurrency wallet extensions and 14 password managers. Stolen data is stored in hidden folders, encrypted using AES-256-GCM, and packaged into hidden ZIP archives before being uploaded.
Warning signs of infection include a website requiring a meeting PIN for download, unexpected password prompts, and unfamiliar apps requesting Full Disk Access. Users are advised to download apps from verified sources, avoid overriding security warnings, pause before entering passwords, review app permissions, install security updates, use antivirus software, and act quickly if they installed Werkbit Setup.