It looks like Apple. It behaves like Apple. It is very much not Apple.
Security researchers at Jamf Threat Labs have identified a new piece of macOS malware called CrashStealer, a sophisticated information stealer that impersonates Apple’s built-in crash-reporting framework. The malware targets browser-stored crypto wallet credentials, Keychain secrets, and data from roughly 80 cryptocurrency wallet extensions, making it a direct threat to anyone managing digital assets on a Mac.
Jamf first spotted CrashStealer in development during May 2026. By early July, it had graduated from research samples to active attacks, a timeline of roughly six weeks from prototype to deployment.
How CrashStealer actually works
The malware uses a notarized dropper called Werkbit.app, signed under Developer ID Emil Grigorov, to get past Apple’s Gatekeeper protections.
Once installed, the payload stages itself inside a hidden /tmp directory and establishes persistence through a LaunchAgent, meaning it survives reboots and runs quietly in the background.
The bundle ID it uses is com.apple.crashreporter, Apple’s own identifier for crash-reporting software. To an average user checking their system, the process looks completely routine.
From there, CrashStealer gets to work. It targets browser credentials, macOS Keychain secrets, and data stored by approximately 14 different password managers. It also has the ability to unlock the Keychain and perform local password validation, which means it can actively verify stolen credentials rather than just collecting them.
All of that stolen data gets encrypted using AES-GCM before transmission, then exfiltrated to attacker-controlled servers via libcurl.
Jamf reported the misuse of the Developer ID to Apple for further investigation.
Why crypto users are the primary target
CrashStealer’s scope includes around 80 cryptocurrency wallet browser extensions.
Browser-based wallets are a persistent weak point in crypto security. A hardware wallet stored offline is immune to this kind of theft. A browser extension wallet is not — the seed phrase or private key often lives in the browser’s local storage or memory, and any sufficiently capable infostealer that can read that data can effectively empty the wallet without ever touching a blockchain in a way that alerts the owner.
What makes CrashStealer notable is the combination of Gatekeeper bypass via a signed certificate, impersonation of a native Apple process, and the breadth of its targeting across both wallets and password managers simultaneously.
What this means for crypto holders and market security
The malware’s ability to target 14 different password managers simultaneously is particularly relevant for anyone who uses a password manager to store exchange API keys, recovery phrases, or two-factor backup codes. Password managers become a single point of failure if the machine running them is compromised at the operating system level.
The signed dropper angle is worth watching as a broader trend. Obtaining legitimate developer certificates and using them for malware delivery is a tactic that raises the bar for detection significantly. Traditional security advice to trust notarized Mac software provides less protection when the notarized software is itself the threat vector.
Practically speaking, crypto users on macOS should treat browser-based wallets as hot wallets in the riskiest sense of the term. Significant holdings belong on hardware wallets. Seed phrases belong written on paper, stored offline, and nowhere near a browser, a password manager, or a machine connected to the internet. Any macOS security tool that flags unexpected use of com.apple.crashreporter bundle identifiers should be treating that as an immediate red flag.
Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.

4 hours ago
2















English (US) ·