PamStealer Mac Malware Uses Live Server Decryption to Evade Analysis

PamStealer Mac Malware Uses Live Server Decryption to Evade Analysis

September 30, 2026 • 4 min read

PamStealer, a Mac information stealer first uncovered earlier this year, is already becoming more difficult to analyze and remove. A new version uses an attacker-controlled server to help decrypt its main payload, adds several overlapping persistence methods, and replaces the Rust-based stealer seen in earlier attacks with a new version written in Swift.

The latest variant was documented by Jamf Threat Labs, which describes it as the third known version of PamStealer. The malware is still focused on stealing passwords, browser information and other sensitive data, but much of the machinery around that theft has been redesigned.

From Fake Clipboard Apps to a Fake Crypto Wallet

Jamf first documented PamStealer in July after finding it distributed through a fake website impersonating Maccy, a legitimate Mac clipboard manager. Later campaigns used additional clipboard-app lures, while the newest campaign has shifted to a fake multichain cryptocurrency wallet called Wavel.

According to Jamf’s latest investigation, the Wavel website delivered a disk image containing a compiled AppleScript file. Opening it launches Apple’s Script Editor, where the victim is instructed to run the script. That distinction matters: the research does not describe a drive-by attack that compromises a Mac simply by visiting the website. The user still has to download and execute the malicious file.

The Payload Now Depends on a Live Server

The biggest technical change is how PamStealer unlocks its next stage. Jamf found that the new chain downloads a utility called pkgunpack, which generates a fresh cryptographic key pair and communicates with attacker-controlled infrastructure. The system uses X25519 key exchange and AES-256-GCM encryption, with the server providing information needed to decrypt the payload.

Because a new key pair is generated for each execution, obtaining the encrypted malware by itself is no longer enough to simply decrypt it later using material recovered from the downloader. This gives the operators more control over when the second stage can be unlocked and makes offline analysis more difficult. The Hacker News also highlighted the live C2-assisted decryption in its coverage of the new variant.

This should not be confused with proof of a traditional interactive remote-control backdoor. What the research demonstrates is a live server-side exchange required as part of the payload decryption and delivery process.

PamStealer Is Also Harder to Remove

Once decrypted, Jamf says the malware installs its malicious application inside the user’s Library directory under the name Finder.app and creates a LaunchAgent so it can start automatically. It also includes a local repair mechanism capable of restoring parts of the infection if they are removed.

The malware modifies the user’s .zshrc file so opening an interactive zsh shell can trigger its repair script. It also changes Git’s global hooks configuration and creates malicious post-checkout and pre-commit hooks. On a developer’s Mac, ordinary Git activity such as checking out code or committing changes could therefore cause the repair mechanism to run again. Jamf describes multiple redundant persistence and repair paths, making partial removal less likely to actually eliminate the infection.

Passwords, Keychains and Browser Data Remain the Goal

The final stealer has been rewritten in Swift, but one of PamStealer’s signature tricks remains. It can display a fake macOS authentication prompt and validate the password entered by the victim using macOS Pluggable Authentication Modules, or PAM. The original Jamf research showed how this lets the malware determine whether a captured password is actually correct instead of simply accepting whatever the user types.

In the newest sample, Jamf found functionality for accessing macOS Keychain data and targeting browser information from 17 browsers, including Chrome, Firefox, Edge, Brave, Arc, Vivaldi, Opera, Waterfox and LibreWolf. During dynamic analysis, researchers also observed collection of system information, user files and other data before the material was packaged into a ZIP archive and uploaded to attacker-controlled infrastructure.

PamStealer’s internals are getting considerably more sophisticated, but the infection still starts with a familiar problem: convincing someone to run software they should not trust. The Wavel campaign documented by Jamf Threat Labs requires the victim to download the fake application and manually execute its script in Script Editor.

For Mac users, an application download that unexpectedly opens Script Editor, Terminal or asks for commands to be run manually should be treated as a major warning sign. The latest PamStealer does not appear to remove the need for social engineering; it makes what happens after that initial mistake harder to inspect, harder to clean up and more resilient than the versions researchers were examining only a few months ago.