CrashStealer Malware Impersonates Apple Tool to Steal Mac Passwords and Crypto - MacRumorsOpen MenuShow RoundupsShow Forums menuVisit ForumsOpen Sidebar
Skip to Content

CrashStealer Malware Impersonates Apple Tool to Steal Mac Passwords and Crypto

Mac users should watch out for macOS malware called CrashStealer, according to Jamf Threat Labs. The malware impersonates Apple's crash reporting framework, and it's meant to steal all kinds of sensitive information.

bug security vulnerability issue fix larry
CrashStealer collects browser data, password manager data, cryptocurrency wallet extensions, and keychain data, and Jamf first noticed it circulating in a fake Apple-notarized app called Werkbit. With notarization, the malware is not stopped by Gatekeeper, which is part of the macOS security system.

It targets more than 80 cryptocurrency wallet extensions, and 14 password managers like 1Password, LastPass, and Dashlane. It searches through the Document and Downloads folders to look for information worth collecting.

The app looks legitimate and uses a typical macOS install procedure for software downloaded through the web, with the process detailed on Jamf's website. A fake CrashReporter.app is downloaded through Werkbit, and it's meant to impersonate Apple's own crash reporter. A user clicking on the app would likely see it as a legitimate Apple utility.

It requests full disk access "for system administration," and uses a native password prompt that looks like a genuine macOS authorization request. The password entered is used to access the login keychain. Data collected is encrypted with AES–256-GCM through Apple's CommonCrypto and sent to the attacker's IP address.

Jamf says the way CrashStealer was implemented "shows real care," with the concealment steps setting it apart from standard infostealers. The malware was reported to Apple after first being spotted in May and found actively in use in July.

Apple revoked the Werkbit app's signing credentials, so the specific attack vector outlined by Jamf has been disabled, but the malware could surface again. The original version was gated behind a PIN required for installation, suggesting it was aimed at specific people.

Apple's notarization system is meant to protect Mac users from malware, and Apple says that notarized apps are checked for malicious components. CrashStealer makes it clear there are methods for hiding malware from Apple's security process.

When downloading software, users can protect themselves from CrashStealer by being aware that Apple's crash reporter is built-in. Any download that uses CrashReporter is a red flag, as is an app that asks for a system password right when it's launched.

Tag: Malware

Popular Stories

Apple Event Logo

Apple Working on All-New Operating System

Wednesday July 29, 2026 11:39 am PDT by
Apple is developing an all-new operating system that is essentially a mix of tvOS, watchOS, and iOS, according to Bloomberg's Mark Gurman. In a report this week, he said the operating system will feature a grid of icons, widgets, and apps, along with customizable clock faces. The new software platform is intended for Apple's long-rumored smart home hub. With built-in facial recognition,...
imac video apple feature

Apple Made Its Second-Biggest Acquisition Ever This Year

Wednesday July 29, 2026 12:03 pm PDT by
Apple this year acquired Israeli startup Q.ai for close to $2 billion, according to the Financial Times. That would make this Apple's second-biggest acquisition ever, after it paid $3 billion for the popular headphone maker Beats in 2014. This is also the largest known Apple acquisition since the company purchased Intel's smartphone modem business and patents for $1 billion in 2019. Q.ai...
Dynamic Island iPhone 18 Pro Feature

iPhone 18 Pro: Twelve Changes Coming to Apple's Next Flagship

Thursday July 30, 2026 3:43 am PDT by
We're less than two months out from the launch of Apple's premium next-generation smartphone lineup, and while we're not expecting a dramatic change in terms of functionality, there are still several enhancements rumored to be coming to the iPhone 18 Pro and iPhone 18 Pro Max. One thing worth noting is that Apple is reportedly planning a major change to its iPhone release cycle this year,...

Top Rated Comments

Skwoodge Avatar
2 weeks ago

People would say for years that Macs can’t get malware, but that was mainly a result of Macs having such a low market share compared to the PC market

That has changed and now Macs are much more susceptible to getting these kinds of malware attacks than they used to be in the past
It was never true that Macs can't get malware, but macOS is definitely a more popular target now. However, most malware still requires inputting your password because of Apple's multi-layered security, so you need to be careful what things you give access to your password.
Score: 15 Votes (Like | Disagree)
TheDailyApple Avatar
2 weeks ago

It was never true that Macs can't get malware, but macOS is definitely a more popular target now. However, most malware still requires inputting your password because of Apple's multi-layered security, so you need to be careful what things you give access to your password.
Unfortunately social engineering makes users the weak link security-wise.
Score: 14 Votes (Like | Disagree)
IJ Reilly Avatar
2 weeks ago
Reports of this kind are decidedly unhelpful for nontechnical readers, and probably little use to the technical, either. This payload was apparently attached to an app called "Werkbit," but the story provides no information on this app, how it came to include this code, or why anyone would have downloaded it. Is this merely a proof of concept for a much wider deployment? Could it be attached to other apps, and we simply don't know about it yet? Gosh, wouldn't that be something to know?
Score: 11 Votes (Like | Disagree)
2 weeks ago

Notarization from Apple is a joke. It in fact gives the user a false sense of security while it is just a registration process based on good will.
What a strange take. Apple has already used their notarization system to disable this installer. I’m not sure how the social engineering of this malware worked but if you install things from the web, it is incumbent on the user to make sure the source is reliable.

No OS vendor can prevent something like this. All they can do is take action once it is reported. Which is exactly what Apple did.
Score: 6 Votes (Like | Disagree)
Justin Cymbal Avatar
2 weeks ago
People would say for years that Macs can’t get malware, but that was mainly a result of Macs having such a low market share compared to the PC market

That has changed and now Macs are much more susceptible to getting these kinds of malware attacks than they used to be in the past
Score: 4 Votes (Like | Disagree)
2 weeks ago
Always good to be careful. Malware targeting Macs are increasing.
Score: 3 Votes (Like | Disagree)

🔗 Related Apple News & Rumors

Stay updated with the latest Apple ecosystem news and verified rumors