PamStealer Malware Targeted macOS Users via Fake Wallet
A new campaign disguised malicious software as a cryptocurrency wallet to harvest sensitive data from Apple devices.
Updated on Sept. 23, 2026 in Cybersecurity

Live Poll
Do you feel confident in your ability to identify fake applications on your devices?
Hackers have distributed a new macOS-specific malware dubbed PamStealer through a fraudulent cryptocurrency wallet application called Wavel. The malicious software is designed to exfiltrate user credentials, browser data, and Keychain items from infected systems.
Why it matters
This campaign illustrates a shift toward more sophisticated evasion and persistence tactics in attacks targeting the macOS ecosystem. The use of impersonated financial tools highlights the persistent risk posed to users of decentralized finance applications.
The PamStealer malware uses a Swift-based payload and a server-assisted decryption chain to bypass security measures. These mechanisms allow the software to maintain persistence on target devices while evading standard detection.
The players
Wavel
The name of the fake cryptocurrency wallet application used to disguise and distribute the PamStealer malware.
The details
The PamStealer malware functions by masquerading as the Wavel cryptocurrency wallet, tricking users into installing the payload on their macOS devices. Once active, the software leverages a server-assisted decryption chain, where parts of the decryption logic are processed remotely to prevent local analysis of the malicious code. The payload, written in the Swift programming language, is designed to harvest sensitive information including Keychain items, which serve as the secure storage for passwords and cryptographic keys on Apple hardware.
Timeline
September 23, 2026: The PamStealer campaign was documented in a security report.
The Tech Race
This campaign underscores the ongoing arms race between developers of macOS security tools and attackers seeking to compromise Apple's hardware architecture. It follows a trend of increasingly complex malware payloads that attempt to bypass integrated features like the macOS Keychain.
Users should exercise caution when downloading cryptocurrency applications and ensure all software is sourced exclusively from official developer portals or the Mac App Store. Those who installed the Wavel application should immediately audit their system Keychain and rotate all stored credentials.
The takeaway
The PamStealer campaign serves as a reminder that even secure operating systems are vulnerable to social engineering via impersonated software. Users should watch for future security updates from Apple that address the specific evasion techniques utilized by Swift-based payloads.
Further reading
Explore ongoing threats to endpoint security in the Cybersecurity section.
Live Poll
Do you feel confident in your ability to identify fake applications on your devices?






