Newly discovered PamStealer isn’t your typical macOS malware
This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).
Researchers at Jamf have discovered PamStealer, a novel macOS infostealer that uses a multi-stage delivery chain to evade detection. It arrives disguised as the Maccy clipboard manager in a disk image, uses an AppleScript lure that bypasses macOS quarantine via Command-R execution, and drops a Rust-written second stage that leverages macOS's Pluggable Authentication Modules (PAM) to locally validate stolen credentials before exfiltrating them. The second stage impersonates Finder, encrypts C2 traffic, and deliberately delays prompts like Full Disk Access requests by up to 40 minutes to avoid correlation with launch time — making it significantly stealthier than typical commodity macOS stealers.