← Back to feed
Threat Actors & CampaignsEmerging1 sourceSep 23, 2026 · 09:24via CyberPress

PamStealer macOS Infostealer Targets Crypto Wallets and Steals User Credentials

Brief

A new PamStealer variant is targeting macOS users through a fake cryptocurrency wallet installer. In research published on September 22, Jamf Threat Labs said the malware steals passwords and browser data while using a server-controlled decryption process that makes its payload harder to analyze.

The attack begins at wavel[. ]app , a site impersonating a multichain crypto wallet. Its macOS download button delivers a disk image containing a compiled . scpt file.

Because Finder normally hides file extensions, the file can appear to be an ordinary document. If a user opens it in Script Editor and follows the displayed instructions, embedded JavaScript for Automation runs a hidden zsh dropper.

The dropper downloads a tool called pkgunpack and an encrypted payload from wavel. apple03cloudstore[. ]com . Unlike earlier PamStealer variants, it does not carry the payload’s decryption key.

Read more on CyberPress