
Security researchers at Jamf Threat Labs have discovered a piece of Mac malware called PamStealer that’s unusually sneaky about stealing your login password. It disguises itself as Maccy — a legitimate and popular free clipboard manager for Mac — and lures victims to a fake site (maccyapp[.]com) that looks nearly identical to the real app’s homepage. When you download and run the fake Maccy app, it immediately shows you a genuine-looking macOS password prompt: the same style dialog your Mac uses when an app requests your system password.
Here’s the trick: if you type the wrong password, the prompt simply reappears and asks again. The malware secretly checks each entry against your Mac’s authentication system (the PAM API) until it receives the correct one. Once it has your real password, it shows a fake error message — “Maccy is damaged and can’t be opened. You should move it to the Trash” — and quietly runs a second, hidden program in the background. That program is a sophisticated information stealer built in the Rust programming language. It harvests passwords and session cookies from your web browsers, data from cryptocurrency wallets, and other sensitive files, then sends everything to the attackers over an encrypted connection.
How to check if you’re affected
Affected devices are any Mac where a “Maccy” app was downloaded from a site other than the real maccy.app. To check: open your Applications folder and look for a Maccy app you don’t recall intentionally installing. If you’re unsure about its origin, open the Maccy website (maccy.app) to confirm the real app’s appearance and download link — and compare against what you have. You should also check your Mac’s saved passwords in System Settings → Passwords and in any password manager you use. If PamStealer ran on your machine, assume your system password and any browser-saved credentials have been compromised and change them immediately.
