PamStealer uses live C2 decryption and layered macOS persistence

Jamf Threat Labs has identified a new PamStealer macOS variant that requires a live command-and-control server to decrypt its main payload. The campaign uses a fake cryptocurrency-wallet site, wavel[.]app, to distribute a disk image named Wavel.dmg, then combines a JavaScript for Automation carrier, a zsh dropper and four redundant persistence mechanisms.
The change means analysts cannot recover the second-stage payload through static inspection alone. The server retains the private key required to complete the exchange, while the malware generates a new ephemeral keypair on each execution. A captured Data Encryption Key therefore cannot simply be replayed to unpack the payload.
From fake wallet site to server-assisted decryption
Visitors who select “Download for macOS” on the bogus Wavel site receive a disk image containing a compiled AppleScript. Opening it launches Apple’s Script Editor with instructions that trigger execution of a JXA dropper. Earlier PamStealer variants embedded key material in JXA and used RC4 to decrypt their payloads locally; the Wavel sample instead uses JXA primarily as a carrier.
When Script Editor runs the file, the JXA component decodes a base64 string and pipes it to /bin/zsh -s. The JXA process exits, while zsh continues in the background. The decoded script downloads and invokes a utility called pkgunpack from wavel.apple03cloudstore[.]com, performs an X25519 key exchange, decrypts and stages the payload bundle, and polls the staging directory for ZIP upload.
This live decryption model adds another obstacle to investigations of macOS delivery chains. The broader context in macOS living-off-the-land techniques shows how macOS living-off-the-land techniques can reduce the visibility of malicious activity, while this PamStealer version adds server-controlled cryptographic gating to the delivery process.
Persistence reaches shell sessions and Git activity
The zsh script suppresses macOS notifications that warn users about newly added background login items. It installs a LaunchAgent and a repair script designed to restore both the payload bundle and the LaunchAgent if either is removed. A hook added to ~/.zshrc starts that repair script whenever a new interactive zsh session opens.
The repair script is also copied into post-checkout and pre-commit folders under ~/Library/Application Support/System/.githooks/. By setting the global core.hooksPath configuration, the malware causes Git checkout and commit operations in any repository on the compromised Mac to activate the repair script silently.
Swift stealer broadens browser coverage
The final stealer is written in Swift rather than the Rust used by its predecessor. It displays a fake crash dialog to collect a system password and validates submitted credentials with a PAM-based approach. It also enumerates Keychain items, fingerprints the system, captures profile and application information, and gathers files including .zsh_history, .zshrc, .bash_history and .gitconfig.
Its browser targets include Google Chrome, Microsoft Edge, Mozilla Firefox, Brave, Vivaldi, Opera, Opera GX, Arc, Zen, Waterfox, LibreWolf, Yandex Browser and Cốc Cốc. For businesses, the practical implication is to investigate unexpected DMG downloads, Script Editor execution and new login items promptly, while checking LaunchAgents, shell startup files and global Git hook paths for unauthorized changes.

