It looks like Apple. It behaves like Apple. It is very much not Apple.

Security researchers at Jamf Threat Labs have identified a new piece of macOS malware called CrashStealer, a sophisticated information stealer that impersonates Apple’s built-in crash-reporting framework. The malware targets browser-stored crypto wallet credentials, Keychain secrets, and data from roughly 80 cryptocurrency wallet extensions, making it a direct threat to anyone managing digital assets on a Mac.

Jamf first spotted CrashStealer in development during May 2026. By early July, it had graduated from research samples to active attacks, a timeline of roughly six weeks from prototype to deployment.

How CrashStealer actually works

The malware uses a notarized dropper called Werkbit.app, signed under Developer ID Emil Grigorov, to get past Apple’s Gatekeeper protections.