FeedMalwareNew macOS malware PamStealer uses PAM to validate stolen dat...
MalwareCyber Insider
8.5CRITICAL

New macOS malware PamStealer uses PAM to validate stolen data

📅 3 July 2026 at 15:25 UTC📰 Cyber InsiderView original source ↗
New macOS malware PamStealer uses PAM to validate stolen data

A previously undocumented macOS infostealer dubbed PamStealer validates victims' macOS passwords through the OS’s Pluggable Authentication Modules (PAM) before stealing them. Jamf Threat Labs researchers, who analyzed a two-stage attack chain combining AppleScript, JavaScript for Automation (JXA), and a Rust payload, report that attackers distribute PamStealer through the fake domain maccyapp[.]com, which impersonates the legitimate … The post New macOS malware PamStealer uses PAM to validate stolen data appeared first on CyberInsider.

🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview

PamStealer is a macOS infostealer that uses PAM to validate stolen data, targeting Apple Silicon Macs and silently exiting on Intel systems or devices configured for former Soviet countries. The malware steals browser credentials, cookies, cryptocurrency wallet data, clipboard contents, and keychain information.

⚙️Technical Details
Affected Systems
Apple Silicon Macs
Attack Vectors
Fake domain maccyapp[.]com distribution through a disk image containing a compiled AppleScriptNative macOS APIs through JXA and NSURLSession to fetch the second-stage payload
💥Impact Assessment
Severity: critical
🛡️Recommended Actions
1Monitor for Script Editor making outbound network connections
2Watch for processes masquerading as Finder while repeatedly executing pbpaste
3Verify login item registrations and watch for unsolicited requests for Full Disk Access
📦Affected Products
Macos: Apple Silicon Macs

Read the full article

This is a curated summary. The complete article is available at Cyber Insider.

Read on Cyber Insider
← Back to feed