PamStealer has appeared in a new macOS variant that uses a server-side decryption chain, making the payload impossible to recover statically without live C2 cooperation. The campaign lures victims through a fake Wavel cryptocurrency wallet site and ultimately steals passwords, keychain items, browser credentials, and system data from compromised Macs. #PamStealer #Wavel #JamfThreatLabs #macOS
Keypoints
- The new PamStealer version relies on a server-side decryption chain for payload recovery.
- A fake Wavel website delivers the malicious Wavel.dmg file to macOS victims.
- The JXA layer now acts only as a carrier before handing execution to a zsh dropper.
- The attack uses pkgunpack, X25519 key exchange, and ephemeral keys to block static analysis.
- The Swift stealer collects passwords, keychain items, browser credentials, and system metadata.
Read More: https://thehackernews.com/2026/09/pamstealer-macos-malware-adds-live-c2.html