PamStealer Malware Targeted macOS Users via Fake Wallet

A new campaign disguised malicious software as a cryptocurrency wallet to harvest sensitive data from Apple devices.

Updated on Sept. 23, 2026 in Cybersecurity

Isometric editorial illustration of a complex block-based digital structure with glowing connections, representing data exfiltration from a secure system.
A new malware campaign, dubbed PamStealer, is targeting macOS users by masquerading as a cryptocurrency wallet to steal sensitive Keychain credentials. AI Illustration. Upload story photo >

Live Poll

Do you feel confident in your ability to identify fake applications on your devices?

Hackers have distributed a new macOS-specific malware dubbed PamStealer through a fraudulent cryptocurrency wallet application called Wavel. The malicious software is designed to exfiltrate user credentials, browser data, and Keychain items from infected systems.

Why it matters

This campaign illustrates a shift toward more sophisticated evasion and persistence tactics in attacks targeting the macOS ecosystem. The use of impersonated financial tools highlights the persistent risk posed to users of decentralized finance applications.

The PamStealer malware uses a Swift-based payload and a server-assisted decryption chain to bypass security measures. These mechanisms allow the software to maintain persistence on target devices while evading standard detection.

The players

Wavel

The name of the fake cryptocurrency wallet application used to disguise and distribute the PamStealer malware.

The details

The PamStealer malware functions by masquerading as the Wavel cryptocurrency wallet, tricking users into installing the payload on their macOS devices. Once active, the software leverages a server-assisted decryption chain, where parts of the decryption logic are processed remotely to prevent local analysis of the malicious code. The payload, written in the Swift programming language, is designed to harvest sensitive information including Keychain items, which serve as the secure storage for passwords and cryptographic keys on Apple hardware.

Timeline

  1. September 23, 2026: The PamStealer campaign was documented in a security report.

The Tech Race

This campaign underscores the ongoing arms race between developers of macOS security tools and attackers seeking to compromise Apple's hardware architecture. It follows a trend of increasingly complex malware payloads that attempt to bypass integrated features like the macOS Keychain.

Users should exercise caution when downloading cryptocurrency applications and ensure all software is sourced exclusively from official developer portals or the Mac App Store. Those who installed the Wavel application should immediately audit their system Keychain and rotate all stored credentials.

The takeaway

The PamStealer campaign serves as a reminder that even secure operating systems are vulnerable to social engineering via impersonated software. Users should watch for future security updates from Apple that address the specific evasion techniques utilized by Swift-based payloads.

Further reading

Explore ongoing threats to endpoint security in the Cybersecurity section.

Live Poll

Do you feel confident in your ability to identify fake applications on your devices?