It looks like Apple. It behaves like Apple. It is very much not Apple.
Security researchers at Jamf Threat Labs have identified a new piece of macOS malware called CrashStealer, a sophisticated information stealer that impersonates Apple’s built-in crash-reporting framework. The malware targets browser-stored crypto wallet credentials, Keychain secrets, and data from roughly 80 cryptocurrency wallet extensions, making it a direct threat to anyone managing digital assets on a Mac.
Jamf first spotted CrashStealer in development during May 2026. By early July, it had graduated from research samples to active attacks, a timeline of roughly six weeks from prototype to deployment.
How CrashStealer actually works
The malware uses a notarized dropper called Werkbit.app, signed under Developer ID Emil Grigorov, to get past Apple’s Gatekeeper protections.













