New PamStealer Malware Uses Stealthy Tradecraft to Target macOS Users
SOFTWARETECHNOLOGY
Published:July 2, 2026
Affected Company:Security Researchers

New PamStealer Malware Uses Stealthy Tradecraft to Target macOS Users

Researchers uncovered PamStealer, a Rust-based macOS infostealer disguised as the Maccy clipboard app that abuses Apple's authentication system to validate stolen passwords before exfiltrating them.

Security researchers have identified PamStealer, a previously unseen macOS credential-stealing malware distributed via a disk image disguised as the Maccy clipboard manager. Its AppleScript-based first stage delivers a Rust-written second stage.

Unusually, PamStealer abuses macOS's Pluggable Authentication Modules interface to validate a victim's password locally before stealing it, reflecting growing sophistication in Mac-targeted infostealers.