Industry
Newly discovered PamStealer isn't your typical macOS malware
PamStealer is a macOS infostealer disguised as the legitimate Maccy clipboard manager that uses a two-stage attack chain to silently harvest data and clipboard contents while evading detection. The ma
PamStealer is a macOS infostealer disguised as the legitimate Maccy clipboard manager that uses a two-stage attack chain to silently harvest data and clipboard contents while evading detection. The malware is named for its unique behavior of validating victim passwords through macOS Pluggable Authentication Modules (PAM) before harvesting them, creating a quieter execution chain than typical commodity macOS stealers. It combines a compiled AppleScript dropper with native JavaScript for Automation (JXA) and a Rust-based second-stage payload responsible for credential theft, browser data collection, and persistence.
Source: Ars Technica | 2026-07-02