CrashStealer Malware Impersonates Apple Tool to Steal Mac Passwords and Crypto - MacRumors
Skip to Content

CrashStealer Malware Impersonates Apple Tool to Steal Mac Passwords and Crypto

Mac users should watch out for macOS malware called CrashStealer, according to Jamf Threat Labs. The malware impersonates Apple's crash reporting framework, and it's meant to steal all kinds of sensitive information.

bug security vulnerability issue fix larry
CrashStealer collects browser data, password manager data, cryptocurrency wallet extensions, and keychain data, and Jamf first noticed it circulating in a fake Apple-notarized app called Werkbit. With notarization, the malware is not stopped by Gatekeeper, which is part of the macOS security system.

It targets more than 80 cryptocurrency wallet extensions, and 14 password managers like 1Password, LastPass, and Dashlane. It searches through the Document and Downloads folders to look for information worth collecting.

The app looks legitimate and uses a typical macOS install procedure for software downloaded through the web, with the process detailed on Jamf's website. A fake CrashReporter.app is downloaded through Werkbit, and it's meant to impersonate Apple's own crash reporter. A user clicking on the app would likely see it as a legitimate Apple utility.

It requests full disk access "for system administration," and uses a native password prompt that looks like a genuine macOS authorization request. The password entered is used to access the login keychain. Data collected is encrypted with AES–256-GCM through Apple's CommonCrypto and sent to the attacker's IP address.

Jamf says the way CrashStealer was implemented "shows real care," with the concealment steps setting it apart from standard infostealers. The malware was reported to Apple after first being spotted in May and found actively in use in July.

Apple revoked the Werkbit app's signing credentials, so the specific attack vector outlined by Jamf has been disabled, but the malware could surface again. The original version was gated behind a PIN required for installation, suggesting it was aimed at specific people.

Apple's notarization system is meant to protect Mac users from malware, and Apple says that notarized apps are checked for malicious components. CrashStealer makes it clear there are methods for hiding malware from Apple's security process.

When downloading software, users can protect themselves from CrashStealer by being aware that Apple's crash reporter is built-in. Any download that uses CrashReporter is a red flag, as is an app that asks for a system password right when it's launched.

Tag: Malware

Popular Stories

Apple Logo Gradient 16x9 1

Apple Just Made an Extremely Rare Product Announcement

Thursday August 27, 2026 7:58 am PDT by
The new Mac mini and Mac Studio models unveiled by Apple this week are the company's first new Macs announced in August since 2020. It is extremely rare for Apple to announce new products of any kind in August, excluding smaller things like new color options and accessories. As mentioned, Apple's last notable August product announcement was in 2020, when it updated the 27-inch iMac and a...
Apple Surprise Shine

Apple Event: Six New Products to Expect on September 9

Thursday August 27, 2026 8:00 am PDT by
Apple has announced that it will be holding an event on Wednesday, September 9 at 10 a.m. Pacific Time, with the company widely expected to unveil the iPhone 18 Pro, iPhone 18 Pro Max, its first-ever foldable iPhone, and more. Other products expected to be announced at the event include an Apple Watch Series 12 with a ceramic case option, an Apple Watch Ultra 4, AirPods 5 with and without...
iPhone 18 Pro Dark Cherry Feature

iPhone 18 Pro Pre-Orders May Start at an Unusual Time

Friday August 28, 2026 8:17 am PDT by
Pre-orders of Apple's iPhone 18 Pro may not open until Saturday, September 12, a day later than the company's usual schedule, according to a new report. Apple is set to hold its annual iPhone event on Wednesday, September 9, where the iPhone 18 Pro models, its first-ever foldable iPhone, and the Apple Watch Series 12 and Ultra 4 are all expected to be announced. Under Apple's typical...

Top Rated Comments

Skwoodge Avatar
6 weeks ago

People would say for years that Macs can’t get malware, but that was mainly a result of Macs having such a low market share compared to the PC market

That has changed and now Macs are much more susceptible to getting these kinds of malware attacks than they used to be in the past
It was never true that Macs can't get malware, but macOS is definitely a more popular target now. However, most malware still requires inputting your password because of Apple's multi-layered security, so you need to be careful what things you give access to your password.
Score: 15 Votes (Like | Disagree)
TheDailyApple Avatar
6 weeks ago

It was never true that Macs can't get malware, but macOS is definitely a more popular target now. However, most malware still requires inputting your password because of Apple's multi-layered security, so you need to be careful what things you give access to your password.
Unfortunately social engineering makes users the weak link security-wise.
Score: 14 Votes (Like | Disagree)
IJ Reilly Avatar
6 weeks ago
Reports of this kind are decidedly unhelpful for nontechnical readers, and probably little use to the technical, either. This payload was apparently attached to an app called "Werkbit," but the story provides no information on this app, how it came to include this code, or why anyone would have downloaded it. Is this merely a proof of concept for a much wider deployment? Could it be attached to other apps, and we simply don't know about it yet? Gosh, wouldn't that be something to know?
Score: 11 Votes (Like | Disagree)
6 weeks ago

Notarization from Apple is a joke. It in fact gives the user a false sense of security while it is just a registration process based on good will.
What a strange take. Apple has already used their notarization system to disable this installer. I’m not sure how the social engineering of this malware worked but if you install things from the web, it is incumbent on the user to make sure the source is reliable.

No OS vendor can prevent something like this. All they can do is take action once it is reported. Which is exactly what Apple did.
Score: 6 Votes (Like | Disagree)
Justin Cymbal Avatar
6 weeks ago
People would say for years that Macs can’t get malware, but that was mainly a result of Macs having such a low market share compared to the PC market

That has changed and now Macs are much more susceptible to getting these kinds of malware attacks than they used to be in the past
Score: 4 Votes (Like | Disagree)
6 weeks ago
Always good to be careful. Malware targeting Macs are increasing.
Score: 3 Votes (Like | Disagree)