Jamf Threat Labs ha isolato un infostealer in C++ nativo che raggiunge il Mac tramite un finto installer notarizzato da Apple: valida la password in locale con dscl, apre il keychain e cifra il bottino in AES-256-GCM prima di esfiltrarlo.

CrashStealer uses a notarized macOS dropper to pass Gatekeeper, then steals browser, wallet, password manager, file, and keychain data.

A new macOS information-stealing malware called CrashStealer pretends to be Apple's crash-reporting tool to steal credentials, keychain data, and crypto wallets.