PamStealer macOS Infostealer Targets Crypto Wallets and Steals User Credentials
Brief
A new PamStealer variant is targeting macOS users through a fake cryptocurrency wallet installer. In research published on September 22, Jamf Threat Labs said the malware steals passwords and browser data while using a server-controlled decryption process that makes its payload harder to analyze.
The attack begins at wavel[. ]app , a site impersonating a multichain crypto wallet. Its macOS download button delivers a disk image containing a compiled . scpt file.
Because Finder normally hides file extensions, the file can appear to be an ordinary document. If a user opens it in Script Editor and follows the displayed instructions, embedded JavaScript for Automation runs a hidden zsh dropper.
The dropper downloads a tool called pkgunpack and an encrypted payload from wavel. apple03cloudstore[. ]com . Unlike earlier PamStealer variants, it does not carry the payload’s decryption key.
