CrashStealer Malware Impersonates Apple Tool to Steal Mac Passwords and Crypto - MacRumors
Skip to Content

CrashStealer Malware Impersonates Apple Tool to Steal Mac Passwords and Crypto

Mac users should watch out for macOS malware called CrashStealer, according to Jamf Threat Labs. The malware impersonates Apple's crash reporting framework, and it's meant to steal all kinds of sensitive information.

bug security vulnerability issue fix larry
CrashStealer collects browser data, password manager data, cryptocurrency wallet extensions, and keychain data, and Jamf first noticed it circulating in a fake Apple-notarized app called Werkbit. With notarization, the malware is not stopped by Gatekeeper, which is part of the macOS security system.

It targets more than 80 cryptocurrency wallet extensions, and 14 password managers like 1Password, LastPass, and Dashlane. It searches through the Document and Downloads folders to look for information worth collecting.

The app looks legitimate and uses a typical macOS install procedure for software downloaded through the web, with the process detailed on Jamf's website. A fake CrashReporter.app is downloaded through Werkbit, and it's meant to impersonate Apple's own crash reporter. A user clicking on the app would likely see it as a legitimate Apple utility.

It requests full disk access "for system administration," and uses a native password prompt that looks like a genuine macOS authorization request. The password entered is used to access the login keychain. Data collected is encrypted with AES–256-GCM through Apple's CommonCrypto and sent to the attacker's IP address.

Jamf says the way CrashStealer was implemented "shows real care," with the concealment steps setting it apart from standard infostealers. The malware was reported to Apple after first being spotted in May and found actively in use in July.

Apple revoked the Werkbit app's signing credentials, so the specific attack vector outlined by Jamf has been disabled, but the malware could surface again. The original version was gated behind a PIN required for installation, suggesting it was aimed at specific people.

Apple's notarization system is meant to protect Mac users from malware, and Apple says that notarized apps are checked for malicious components. CrashStealer makes it clear there are methods for hiding malware from Apple's security process.

When downloading software, users can protect themselves from CrashStealer by being aware that Apple's crash reporter is built-in. Any download that uses CrashReporter is a red flag, as is an app that asks for a system password right when it's launched.

Tag: Malware

Popular Stories

iPhone 18 Pro Deep Red Feature

iPhone 18 Pro Launching Next Month With These 12 New Features

Sunday August 9, 2026 1:45 pm PDT by
It is now August, and that means the iPhone 18 Pro and iPhone 18 Pro Max are just a month away. The devices are expected to look similar to the iPhone 17 Pro and iPhone 17 Pro Max, but there will still be many year-over-year changes, with rumored features including a smaller Dynamic Island, 5G via satellite, and more. Apple is expected to unveil the iPhone 18 Pro, iPhone 18 Pro Max, and a...
iPhone 18 Pro Deep Red Feature

iPhone 18 Pro Launching Next Month With These 12 New Features

Thursday August 6, 2026 7:03 am PDT by
It is now August, and that means the iPhone 18 Pro and iPhone 18 Pro Max are just a month away. The devices are expected to look similar to the iPhone 17 Pro and iPhone 17 Pro Max, but there will still be many year-over-year changes, with rumored features including a smaller Dynamic Island, 5G via satellite, and more. Apple is expected to unveil the iPhone 18 Pro, iPhone 18 Pro Max, and a...
iPhone 18 Pro Dark Cherry Feature

iPhone 18 Pro Max's Larger Battery Capacity Allegedly Revealed

Monday August 10, 2026 9:37 am PDT by
The upcoming iPhone 18 Pro Max will be equipped with a nearly 12% larger battery compared to the iPhone 17 Pro Max, according to an apparent leak. An alleged photo of a battery pack for a Chinese model of the iPhone 18 Pro Max with a SIM card tray lists a capacity of 5,391 mAh, up from 4,823 mAh for the equivalent iPhone 17 Pro Max battery. The photo was shared on the Korean platform Naver...

Top Rated Comments

Skwoodge Avatar
4 weeks ago

People would say for years that Macs can’t get malware, but that was mainly a result of Macs having such a low market share compared to the PC market

That has changed and now Macs are much more susceptible to getting these kinds of malware attacks than they used to be in the past
It was never true that Macs can't get malware, but macOS is definitely a more popular target now. However, most malware still requires inputting your password because of Apple's multi-layered security, so you need to be careful what things you give access to your password.
Score: 15 Votes (Like | Disagree)
TheDailyApple Avatar
4 weeks ago

It was never true that Macs can't get malware, but macOS is definitely a more popular target now. However, most malware still requires inputting your password because of Apple's multi-layered security, so you need to be careful what things you give access to your password.
Unfortunately social engineering makes users the weak link security-wise.
Score: 14 Votes (Like | Disagree)
IJ Reilly Avatar
4 weeks ago
Reports of this kind are decidedly unhelpful for nontechnical readers, and probably little use to the technical, either. This payload was apparently attached to an app called "Werkbit," but the story provides no information on this app, how it came to include this code, or why anyone would have downloaded it. Is this merely a proof of concept for a much wider deployment? Could it be attached to other apps, and we simply don't know about it yet? Gosh, wouldn't that be something to know?
Score: 11 Votes (Like | Disagree)
4 weeks ago

Notarization from Apple is a joke. It in fact gives the user a false sense of security while it is just a registration process based on good will.
What a strange take. Apple has already used their notarization system to disable this installer. I’m not sure how the social engineering of this malware worked but if you install things from the web, it is incumbent on the user to make sure the source is reliable.

No OS vendor can prevent something like this. All they can do is take action once it is reported. Which is exactly what Apple did.
Score: 6 Votes (Like | Disagree)
Justin Cymbal Avatar
4 weeks ago
People would say for years that Macs can’t get malware, but that was mainly a result of Macs having such a low market share compared to the PC market

That has changed and now Macs are much more susceptible to getting these kinds of malware attacks than they used to be in the past
Score: 4 Votes (Like | Disagree)
4 weeks ago
Always good to be careful. Malware targeting Macs are increasing.
Score: 3 Votes (Like | Disagree)