Apple users faced a serious threat from a new malware operation involving a phony meeting application known as CrashStealer. This malicious software harvested sensitive passwords and cryptocurrency data from Macs. Attackers manipulated Apple's framework to disguise the app as trustworthy. Fortunately, Apple swiftly responded by revoking the developer’s credentials, effectively ceasing further app distribution.

CrashStealer uses a notarized macOS dropper to pass Gatekeeper, then steals browser, wallet, password manager, file, and keychain data.

A new macOS information-stealing malware called CrashStealer pretends to be Apple's crash-reporting tool to steal credentials, keychain data, and crypto wallets.