Open Source · Apple · Google · Decrypt
Fake Mac Clipboard App Delivers New Password-Stealing Malware
Compiled by KHAO Editorial — aggregated from 1 source. See llms.txt for citation guidance.
★ Tier-1 Source
Mac users searching for the open-source clipboard manager Maccy are being targeted by a fake version of the app that installs a new Rust-based infostealer dubbed PamStealer, according to cybersecurity firm Jamf Threat Labs.
Key facts
- According to the report, the second stage is a Rust-based binary designed for Apple Silicon Macs that disguises itself as Finder or Software Update
- The prompt can appear up to 40 minutes after infection, making it less likely that users will associate it with the original download
- The team are tracking this malware under the name PamStealer after one of its core behaviors: validating the victim’s login password through the macOS Pluggable Authentication Modules (PAM)
- With many stealers, they have seen attackers purchasing Google Ad space to lure users to the malicious app
Summary
Jamf Threat Labs identified a new Rust-based macOS infostealer posing as the Maccy clipboard manager. Researchers also spotted ClickFix-style malware delivered through a sponsored advertisement on X. In a report published on Thursday, Jamf Threat Labs said the campaign uses a lookalike website to distribute a disk image containing a malicious AppleScript file named Maccy.scpt. “We are tracking this malware under the name PamStealer after one of its core behaviors: validating the victim’s login password through the macOS Pluggable Authentication Modules (PAM) before harvesting it,” Jamf Threat Labs wrote.