SOFTWARETECHNOLOGY
Published:July 2, 2026
Affected Company:Security Researchers
New PamStealer Malware Uses Stealthy Tradecraft to Target macOS Users
Researchers uncovered PamStealer, a Rust-based macOS infostealer disguised as the Maccy clipboard app that abuses Apple's authentication system to validate stolen passwords before exfiltrating them.
Security researchers have identified PamStealer, a previously unseen macOS credential-stealing malware distributed via a disk image disguised as the Maccy clipboard manager. Its AppleScript-based first stage delivers a Rust-written second stage.
Unusually, PamStealer abuses macOS's Pluggable Authentication Modules interface to validate a victim's password locally before stealing it, reflecting growing sophistication in Mac-targeted infostealers.