Cybersecurity experts have identified a new variant of the PamStealer malware that introduces a server-side decryption chain to ensure that the main payload can only be accessed through a decryption process initiated by a server This article explores decryption utility wavel. . The latest threat artifacts, as reported by Jamf Threat Labs, continue to utilize the same JavaScript for Automation (JXA) dropper mechanism, but have altered the lure and delivery methods.
However, new victims are now tricked into visiting a fraudulent website called "wavel[. ]app," which advertises a nonexistent cryptocurrency wallet service named Wavel.
The decoded zsh script takes the infection forward by performing the following actions: downloading and invoking the "pkgunpack" decryption utility from "wavel.apple03cloudstore[. ]com", performing the X25519 key exchange, decrypting and staging the payload bundle, suppressing macOS notifications that alert users when a new background login item is added, installing four redundant persistence methods via LaunchAgent, a repair zsh script that restores both the payload bundle and the LaunchAgent if not present, and a shell hook appended to ~/.zshrc that triggers the execution of the repair script on every new interactive zsh session.
Xhaflaire emphasized, "The inclusion of Arc, Zen, and the less common regional and privacy-focused browsers extends the target list noticeably beyond what is typical in commodity macOS stealers." This variant of PamStealer is a deliberate investment in delivery infrastructure.











