A deceptive cryptocurrency wallet download has delivered a new version of the PamStealer malware to macOS users This article explores pamstealer malware macos. . Jamf reported in a document shared with ZeroOwl (ZeroOwl) that the malware now impersonates a multichain wallet instead of the clipboard tool used in the earlier PamStealer Maccy campaign.

Since Finder typically hides extensions, the file might look like an ordinary document until opened in Script Editor, where the user must follow instructions to run it. Just like the deceptive utility prompts targeting Macs, this attack relies on tricking someone into initiating the malicious process rather than exploiting a software vulnerability. The UTF-16BE encoded JXA source (Source – Jamf) revealed additional collection routines for system details, shell history, and the user's account photo.

Defenders can set threat and web controls to block and report similar activity, inspect persistence, and reset exposed passwords from a clean device once the Mac is secured. URL: hxxps://wavel.apple03cloudstore[. ]com/4e7a12e1c294f377/CoreUpdate.pkg.enc (Encrypted payload download) URL: hxxps://wavel.apple03cloudstore[.

]com/v1/loader/dek (Payload-key exchange endpoint) URL: hxxps://wavel.apple03cloudstore[. ]com/v1/loader/log (Reported server endpoint) URL: hxxps://wavel.apple03cloudstore[. ]com/v1/asset (Stolen-data upload endpoint) URL: hxxps://wavel.apple03cloudstore[. ]com/v1/asset/1789753519-10913-1182 (Upload destination observed in the sandbox) Generate a public key I6VuXPzLJfPEXgVRO5ycNXdMWHWvMAkrLMV6OpEuwDw= using X25519.

File paths for persistence and repair include: - ~/Library/LaunchAgents/com.apple.finder.agent.plist - ~/Library/Application Support/System/.repair-run - ~/Library/Application Support/System/.sysnotif-backup.tgz - ~/Library/Application Support/System/.githooks - File names post-checkout and pre-commit Git hooks trigger the repair process. Temporary keypair files: /tmp/.eph-.key, /tmp/.eph-.pub.