Third PamStealer macOS Variant Delivered via Fake Wavel Crypto Wallet, Decrypted Only by Live C2
Jamf Threat Labs documents a third PamStealer variant spread through a fake Wavel crypto-wallet site, using a per-run X25519 key exchange so its Swift stealer can't be analyzed without the live server; it harvests Mac passwords, Keychain data, and browser…
Jamf Threat Labs is tracking a new variant of the macOS infostealer PamStealer — described by Cyber Security News as the third — distributed through wavel[.]app, a fake multichain cryptocurrency wallet site. Victims who open Wavel.dmg run a disguised compiled script with a nearly invisible name, which The Hacker News identifies as a JavaScript for Automation (JXA) dropper that downloads a component named pkgunpack from wavel.apple03cloudstore[.]com and completes an X25519 key exchange with attacker infrastructure. Unlike earlier builds, the decryption key is no longer embedded in the dropper, so the encrypted payload cannot be recovered or statically analyzed without the live server. Once running, the Swift-based stealer displays a fake macOS password prompt (described as a fake crash dialog by The Hacker News), validates the captured password using macOS PAM / the system's normal login validation before exfiltration, dumps the login Keychain, and harvests browser credential stores — Cyber Security News counts 17 browsers, while The Hacker News specifies Chromium and Firefox engines — plus shell history, account details, and cryptocurrency wallet files, per GBHackers. In a sandbox test it archived and uploaded the stolen data. Persistence is layered across a LaunchAgent (which GBHackers reports masquerades as a Finder component), a repair script, a ~/.zshrc hook, and Git hooks, with login items and repair triggers able to restore persistence after removal. No victim count was reported.
- Variant identified by Jamf Threat Labs; Cyber Security News describes it as the third PamStealer variant.
- Distribution vector is wavel[.]app, a fake multichain cryptocurrency wallet site impersonating Wavel; victims open Wavel.dmg and are asked to run a compiled script with a nearly invisible name.
- The Hacker News identifies the dropper as JavaScript for Automation (JXA); it downloads pkgunpack from wavel.apple03cloudstore[.]com.
- Unlike earlier builds, the decryption key is no longer embedded in the dropper; an X25519 key exchange with the server supplies a key for the encrypted payload, preventing offline/static analysis.
- Swift-based stealer shows a fake password prompt (a fake crash dialog per The Hacker News) and validates the password via macOS PAM before exfiltration.
- Data theft covers Keychain items, browser credential stores (17 browsers per Cyber Security News; Chromium and Firefox engines per The Hacker News — sources differ in specificity), shell history, account details, and cryptocurrency wallet…
- In a Jamf sandbox test the stealer archived and uploaded stolen data; no victim count has been reported.
- Persistence spans a LaunchAgent masquerading as a Finder component (per GBHackers), a repair script, a ~/.zshrc hook, and Git hooks, with login items and repair triggers able to re-establish persistence after removal.
Coverage timelineoldest first · each row is one article
- · 3d agoFake Crypto Wallet App Spreads PamStealer Malware to Steal Mac Passwords
Cyber Security News· 61
A fake Mac crypto-wallet app delivers new PamStealer malware that steals passwords and browser credentials.
- · 3d agoFake Crypto Wallet App Delivers PamStealer Malware That Hijacks Mac Credentials
GBHackers· 55
A new PamStealer variant for macOS spreads via a fake crypto wallet, using server-assisted decryption to steal credentials, Keychain data, and crypto assets.
- · 1d ago