Logo
News Ababil
Explore
SYS_NODE: ONLINE // Cyber Security

PamStealer macOS malware: A stealthy two‑stage threat defying detection

DECRYPTED BY: Nova Stirling | TIMESTAMP: 2026-07-03 T 03:40:05 Z | [ 1 MIN READ ]
PamStealer macOS malware: A stealthy two‑stage threat defying detection
1 Min Read
Share

PamStealer macOS malware reveals a new stealth vector

Security researchers have uncovered PamStealer macOS malware, a previously unseen threat that blends custom credential‑stealing code with sophisticated tradecraft to remain hidden on Apple laptops.

The infection unfolds in two stages. The initial payload arrives as a DMG file pretending to be “Maccy,” a popular clipboard manager. Inside, an AppleScript is launched; when a user double‑clicks, the script opens in the native Script Editor, where the malicious routine is nested deep within the file.

“The combination of a disk image and AppleScript is common, but the way PamStealer stitches them together is novel,” said a researcher at Reuters.

The second stage is a Rust‑written infostealer that taps macOS’s Pluggable Authentication Modules (PAM) interface to validate the victim’s login password before exfiltrating it to a command‑and‑control server.

Because the script masquerades as a legitimate utility, traditional antivirus tools often miss it, resulting in ↓ 0% detection in early tests. Analysts recommend scrutinizing DMG sources and disabling unnecessary PAM modules.

For a broader view of macOS threats, see the latest report from Bloomberg.


Dispatch from: Nova Stirling

Aerospace & Space Tech Correspondent

Global Data Feed

More from this Intel

Zero‑Day WordPress Core Flaw Exposes Sites to Unauthenticated Code Execution

Zero‑Day WordPress Core Flaw Exposes Sites to Unauthenticated Code Execution

Jul 19, 2026
Capital One Unveils VulnHunter: Open‑Source AI Tool to Preempt Software Exploits

Capital One Unveils VulnHunter: Open‑Source AI Tool to Preempt Software...

Jul 18, 2026
Brex Reinvents AI Agent Policy with Network‑Level Enforcement, Not Pre‑Written Rules

Brex Reinvents AI Agent Policy with Network‑Level Enforcement, Not Pre‑Written...

Jul 18, 2026
SonicWall SMA zero-day exploited by Inc ransomware

SonicWall SMA zero-day exploited by Inc ransomware

Jul 18, 2026
Brian Chesky X Hack Exposes AI‑Generated Crypto Spam on CEO’s Account

Brian Chesky X Hack Exposes AI‑Generated Crypto Spam on CEO’s...

Jul 17, 2026
Secure Boot Blind Spot: Forgotten Bootloaders Leave Systems Exposed

Secure Boot Blind Spot: Forgotten Bootloaders Leave Systems Exposed

Jul 16, 2026

Join The Elite

Get the top 0.1% global intelligence and market insights delivered directly to your inbox before the masses.

We respect your privacy. No spam.