Breaking News

Fake Apple App Steals Mac Passwords

A new macOS threat called CrashStealer is tricking users by posing as Apple's own CrashReporter tool. Security researchers at Jamf have tracked the malware since May 2026 and found it uses the same name, icon, and system metadata as the legitimate CrashReporter.app, along with a matching LaunchAgent, to appear trustworthy.

What makes this threat notable is its use of an Apple-notarized installer. Since Apple's Gatekeeper security feature is designed to screen apps before allowing them to run, a notarized installer is far less likely to be flagged. Notarization simply means the installer passed Apple's automated scans — it does not mean Apple knowingly approved the malicious software. Attackers exploited that trust gap.

The installer, named "Werkbit Setup," is hosted on a fake software site created in late June. Access requires a meeting PIN, suggesting the campaign targets specific individuals rather than the general public.

Once running, CrashStealer shows a convincing fake system password prompt, similar to what macOS normally displays for admin-level actions. Victims who enter their password unknowingly hand over access to their Keychain, macOS's built-in encrypted vault for stored credentials.

From there, the malware harvests saved browser logins and cookies, cryptocurrency wallet extensions, password manager data, and select files from user folders. Everything is encrypted and sent to an attacker-controlled server.

The takeaway: notarization and Gatekeeper cut down on many risks, but they aren't foolproof. Layered security, cautious user habits, and continuous threat monitoring remain essential — reinforcing the case for behavior-based authentication approaches where your patterns, not just your password, help verify who you are.