VMTech
Discuss a project

PamStealer Mimics Maccy and Steals Passwords on macOS

PamStealer Mimics Maccy and Steals Passwords on macOS

Colleagues, I’d like to draw attention to a cybersecurity threat: Jamf Threat Labs has identified PamStealer for macOS.

The campaign follows a two-stage pattern. First, the malware is distributed through fake Maccy websites; then an AppleScript dropper delivers a Rust infostealer.

The attack checks passwords via PAM, steals data from browsers, iCloud Keychain and the clipboard, and also attempts persistence. In addition, it accounts for Apple Silicon and regional indicators to evade analysis.

Why this matters: campaigns like this show how dangerous fake websites and native macOS mechanisms can be. I would rely only on the official maccy.app domain and strengthen download controls.

How do you verify the source of macOS applications?
#cybersecurity #macOS #infostealer #ThreatIntel

Open analytics
On the site 0 views
min read 1 04.07.2026
On Instagram 2 views
On Instagram 1 reach
Instagram

PamStealer Mimics Maccy and Steals Passwords on macOS

Open the post on Instagram ↗