{"id":62022,"date":"2026-07-04T07:23:37","date_gmt":"2026-07-04T11:23:37","guid":{"rendered":"https:\/\/overcentral.com\/en\/?p=62022"},"modified":"2026-07-04T07:23:37","modified_gmt":"2026-07-04T11:23:37","slug":"pamstealer-macos-malware-maccy","status":"publish","type":"post","link":"https:\/\/overcentral.com\/en\/pamstealer-macos-malware-maccy\/","title":{"rendered":"PamStealer macOS Malware Impersonates Maccy to Steal Data"},"content":{"rendered":"<p>A newly identified macOS information stealer, tracked as <a href=\"https:\/\/overcentral.com\/en\/pamstealer-macos-credential-stealer\/\" title=\"PamStealer Combines Clever Tradecraft to Steal macOS Credentials\" data-iacss-internal=\"1\">PamStealer<\/a>, is actively targeting users by impersonating the popular open-source clipboard manager <a href=\"https:\/\/maccy.app\/\" target=\"_blank\" rel=\"noopener noreferrer\" data-iacss-external=\"1\">Maccy<\/a>, according to research from <a href=\"https:\/\/www.jamf.com\/blog\/pamstealer-macos-malware-impersonates-maccy\/\" target=\"_blank\" rel=\"noopener noreferrer\" data-iacss-external=\"1\">Jamf Threat Labs<\/a>. The malware employs a stealthy two-stage infection chain that leverages native Apple APIs and a Rust-based payload to evade traditional detection methods while harvesting credentials, clipboard contents, browser data, and Keychain entries. This discovery underscores a broader trend of macOS malware maturing in sophistication, borrowing techniques long associated with Windows-based threats to achieve quiet, effective <a href=\"https:\/\/overcentral.com\/en\/microsoft-copilot-searchleak-vulnerability\/\" title=\"Microsoft Copilot SearchLeak Attack Enables One-Click Data Theft\" data-iacss-internal=\"1\">data theft<\/a>.<\/p>\n<h2>How the PamStealer Infection Chain Works<\/h2>\n<p>The attack begins with a malicious disk image named Maccy.dmg that contains a compiled AppleScript file (.scpt). When opened, the file presents the user with harmless-looking instructions prompting them to press Run. This simple social engineering trigger activates hidden malicious code embedded within the script. In the first stage, the AppleScript acts as a lightweight dropper that executes a JavaScript for Automation (JXA) payload using native macOS APIs such as NSURLSession, deliberately avoiding common command-line tools like curl or zsh that might attract scrutiny. This approach reduces visible system activity and helps the malware blend into normal macOS behavior. The script then downloads and installs a second-stage payload, often masquerading the dropped files as legitimate macOS components such as Finder or Software Update.<\/p>\n<h2>Environmental Checks and Region Targeting<\/h2>\n<p>PamStealer includes environment-aware checks before executing its full payload. It generates a unique key based on system attributes including CPU architecture, locale, and time zone. If the device does not match the expected profile, the malware silently exits without triggering any suspicious activity. Notably, the malware avoids systems configured for languages and keyboard layouts associated with Russia and neighboring countries, indicating deliberate targeting of specific geographic regions.<\/p>\n<h2>Data Theft Capabilities of the Rust-Based Payload<\/h2>\n<p>The second stage is a Rust-based Mach-O binary, an implementation choice that remains relatively uncommon in macOS malware. Once active, the infostealer performs credential theft by accessing browser databases via SQLite to extract stored passwords, cookies, and cryptocurrency wallet data. It dynamically loads macOS Security frameworks to <a href=\"https:\/\/overcentral.com\/en\/anthropic-restores-claude-fable-5-access\/\" title=\"Anthropic Restores Claude Fable 5 Access on Wednesday\" data-iacss-internal=\"1\">access<\/a> Keychain data, concealing its capabilities from static analysis tools.<\/p>\n<p>One of the most notable features of PamStealer is its password harvesting technique. The malware displays a fake system prompt asking the user to enter their password, then validates the captured credential locally using macOS Pluggable Authentication Modules (PAM). This ensures only correct credentials are collected and avoids suspicious system calls that could trigger alerts.<\/p>\n<p>Clipboard data is continuously monitored using the built-in pbpaste utility. The malware collects clipboard contents at irregular intervals, potentially capturing sensitive information such as passwords, authentication tokens, or cryptocurrency addresses. For persistence, PamStealer registers itself as a login item using both modern and legacy macOS APIs and drops a helper binary disguised as System Settings. It also attempts to trick users into granting Full Disk Access via fake system alerts, expanding its reach to protected files.<\/p>\n<h2>Command-and-Control and Indicators of Compromise<\/h2>\n<p>The malware communicates with its command-and-control server at avenger-sync[.]live, sending encrypted data using ChaCha20-Poly1305 within JSON requests. Jamf Threat Labs also observed connections to public Ethereum RPC endpoints, suggesting the malware may use blockchain infrastructure for resilient command-and-control or payload retrieval. Additional indicators of compromise include the domains api.sync-master[.]online and avngr.netlify[.]app, along with file paths mimicking macOS system directories such as ~\/Library\/Application Support\/com.apple.finder.core\/.<\/p>\n<h2>What Affected Users Should Do Now<\/h2>\n<p>Anyone who has downloaded a copy of Maccy from unofficial sources or encountered unexpected system prompts asking for credentials should take immediate action. Change passwords for all important accounts from a trusted, uninfected device, enable two-factor authentication wherever available, and monitor accounts for unusual activity. Verify the legitimacy of any macOS application by downloading it only from the official developer website or the Mac App Store. Consider deploying a multi-layered endpoint protection solution that includes behavioral analysis capabilities to detect unusual application behavior, unauthorized Keychain access, and unexpected file system modifications. If you suspect your system has been compromised, run a thorough security scan using a reputable antivirus tool and consult with a cybersecurity professional for a deeper investigation.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A newly identified macOS information stealer, tracked as PamStealer, is actively targeting users by impersonating the popular open-source clipboard manager Maccy, according to research from Jamf Threat Labs. The malware employs a stealthy two-stage infection chain that leverages native Apple APIs and a Rust-based payload to evade traditional detection methods while harvesting credentials, clipboard contents, [&hellip;]<\/p>\n","protected":false},"author":7,"featured_media":90640,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/cards.overcentral.com\/cards\/en\/62022.png","fifu_image_alt":"PamStealer macOS Malware Impersonates Maccy to Steal Data","footnotes":""},"categories":[349],"tags":[],"class_list":["post-62022","post","type-post","status-publish","format-standard","has-post-thumbnail","category-articles"],"fifu_image_url":"https:\/\/cards.overcentral.com\/cards\/en\/62022.png","fifu_image_alt":"PamStealer macOS Malware Impersonates Maccy to Steal Data","_links":{"self":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/62022","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/comments?post=62022"}],"version-history":[{"count":0,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/62022\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/media\/90640"}],"wp:attachment":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/media?parent=62022"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/categories?post=62022"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/tags?post=62022"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}