Protect.Computer
NEWS

New macOS Malware Bypasses Apple Security to Steal Your Passwords

· 1 min read · Malicious byte Device safety
New macOS Malware Bypasses Apple Security to Steal Your Passwords

Researchers at Jamf Threat Labs have discovered CrashStealer, a new type of malware targeting Mac computers. The malware is delivered inside a seemingly normal app called “Werkbit” — and it carries Apple’s official notarization stamp, which normally signals that Apple has reviewed and approved the software. This tricks macOS’s built-in Gatekeeper security system into allowing the app to run without displaying any warnings.

Once installed, CrashStealer runs silently in the background, harvesting a wide range of sensitive information. It targets passwords saved in browsers like Chrome, Edge, and Brave, as well as credentials stored in popular password managers including 1Password, Bitwarden, and LastPass. It also targets roughly 80 different cryptocurrency wallet extensions — including MetaMask, Coinbase Wallet, and Phantom — and can collect files from your Documents and Downloads folders. Everything it finds is sent to the attackers over an encrypted connection.

How to check if you’re affected

Affected devices include any Mac computer where the Werkbit app was downloaded and run, particularly from a disk image (.dmg) file obtained outside the official Mac App Store.

To check: open Finder, navigate to your Applications folder, and look for an app called “Werkbit.” If you find it, delete it immediately. You can also press Command+Shift+G in Finder, type ~/Library/LaunchAgents/, and look for any unfamiliar files. If you installed Werkbit or any unknown disk image recently, change your browser-saved passwords, rotate credentials in any password manager you use, and review your cryptocurrency wallet for unauthorized transactions.

Sources

Related reading