HomeTechnologyNewly discovered PamStealer isn't your typical macOS malware

Newly discovered PamStealer isn't your typical macOS malware

TechnologyJuly 3, 2026
1 min read
Newly discovered PamStealer isn't your typical macOS malware
The discovery underscores the increased effort being poured into Mac infostealers.
Reading Settings

Researchers have found a never-before-seen piece of macOS malware that combines a series of clever tradecraft to infect Macs with stealthy, custom-developed credential-stealing code.

The malware is delivered in two stages. The first is distributed in a disk image that masquerades as Maccy, a clipboard manager for Macs. It’s compiled as AppleScript that is notable for the way it delivers the second stage. The malware is named PamStealer because the Rust-written infostealer uses the Pluggable Authentication Modules interface built into macOS to validate the target’s login password before sending it to an attacker-controlled server.

A quieter execution chain

The use of both disk image and AppleScript is common in malware for Macs. More unusual is the way PamStealer combines them to gain stealth. When the AppleScript is double-clicked, it’s opened in the macOS Script Editor, where the malicious functionality is buried deep within the file.

Read full article

Comments

Source: Ars Technica

Share this article

Related Articles

The Download: US robot restrictions, and ICE’s DNA grab
Aug 046 hours ago

The Download: US robot restrictions, and ICE’s DNA grab

This is today’s edition of The Download, our weekday newsletter that provides a daily dose of what’s going on in the world of technology. Trump’s AI protectionism has come for robotics   —

technologyreview.com6 min read
Read More
‘Everyone Is Doing It’: The Truth About AI in Hollywood
Aug 046 hours ago

‘Everyone Is Doing It’: The Truth About AI in Hollywood

Puck’s Matthew Belloni says AI has quietly become part of everyday filmmaking. The battle now isn’t whether Hollywood will use the technology—it’s who controls what’ll come next.

6a6caf552bba9f4c44a513ef36 min read
Read More