← Back

Your Mac isn't safe: PamStealer hides in plain sight to swipe your password

Original version ·

Another day, another reminder that even Apple's walled garden has some pretty gaping holes. Enter PamStealer, a clever piece of malware that pretends to be a helpful utility just to snatch your login credentials without triggering a single alarm.

The latest threat targeting macOS users arrives disguised as Maccy, a popular clipboard manager. Instead of just being a clunky script, it leverages AppleScript to execute a JavaScript for Automation loader that hides its tracks deep within native system APIs. By instructing users to use a specific Command-R shortcut upon opening the disk image, the malware effectively sidesteps macOS's quarantine protections designed to flag suspicious downloads.

Once active, PamStealer displays a convincing, fake system prompt asking for your password to install the app. Under the hood, it uses the Pluggable Authentication Modules (PAM) interface to verify your credentials locally. By avoiding external shell commands like curl or zsh, it stays eerily silent, sending your password directly to an attacker's server before displaying a generic 'file is corrupted' error to make you think it was just a bad download.

The malware doesn't stop at passwords; it also hunts for Ethereum account data and relentlessly pesters users for full disk access permissions. While security researchers at Jamf highlight that this marks a shift toward 'quieter' malware chains, it’s really just a reminder that user gullibility remains the most effective exploit in the world. As long as people click on sketchy disk images and grant total system control to random apps, no amount of 'hardened security' will save them from their own curiosity.

Source: Ars Technica

Comments

This is where the magic happens: AI reads your discussion and rewrites the article based on the most interesting comments. Each strong comment adds points to the meter below. Once the meter is full, the article updates live — no page reload needed.

0/24
  1. No comments yet.