A new malware has been found on Mac that pretends to be a built-in Apple tool and tricks users into giving up their system password. The CrashStealer virus disguises itself as a crash report utility and hunts for passwords, access to crypto wallets, and Keychain contents. This year, hackers have become noticeably more active. Here’s what you need to watch out for and how to spot the fake.

The new virus is designed to extract all your passwords from your computer
How Mac Viruses Steal Passwords and Data
The new macOS threat was reported by the Jamf Threat Labs research team. Specialists discovered that the program pretends to be a crash reporting system and is designed to steal a wide variety of sensitive data.
The list of what CrashStealer collects is impressive. The virus targets browser data and password managers, crypto wallet extensions, and the Keychain — macOS’s built-in password storage. The program also scans the Documents and Downloads folders looking for anything it can take.
The scope of coverage is also impressive. More than 80 crypto wallet extensions and 14 password managers are targeted, including 1Password, LastPass, and Dashlane. So those most at risk are people who keep crypto access and logins for important services on their Mac. Moreover, one successful launch of such a program instantly breaks the entire security chain: a password manager password opens access to all other accounts at once.
Why macOS Protection Lets Dangerous Apps Through

Recent viruses disguise themselves as standard Apple tools and therefore don’t raise suspicion
The most unpleasant part is how carefully the fake is made. CrashStealer was first spotted in a fake Werkbit application that passed Apple’s notarization — a verification process after which the system considers the program safe. Because of this, Gatekeeper, macOS’s built-in guardian, calmly let the malware through.
After that, everything looks routine. Through Werkbit, a fake CrashReporter.app is downloaded to the computer, copying Apple’s crash reporting tool. The user mistakes the fake for a legitimate utility and doesn’t see anything wrong. The reverse logic works: if macOS blocks an app installation, you should double-check where you downloaded it from rather than look for ways to bypass the restriction.
The key moment is the password request. The program asks for full disk access supposedly for system administration and shows a password entry window indistinguishable from a real macOS authorization prompt. The entered password is immediately put to use: with it, the virus reaches the Keychain. The collected data is encrypted and sent to the attacker’s server.
According to Jamf’s assessment, CrashStealer’s implementation was done with genuine thoroughness, and it’s precisely the masking steps that distinguish it from ordinary data-stealing programs. This isn’t a crude hack job — it’s a well-thought-out tool.
Why CrashStealer Could Appear on Mac Again

The fake application already passed Apple’s verification once and bypassed Gatekeeper, which means it could happen again
There is good news. Apple has revoked the Werkbit application’s signatures, so the specific infection path described by Jamf no longer works. The first traces of the virus were found back in May; in July, it was detected in active use and reported to Apple.
However, it’s too early to relax. Researchers warn that the virus could resurface in a different guise. An interesting detail: the original version required a PIN code for installation. This hints that the attack was prepared for specific individuals rather than mass distribution.
The story also highlighted a vulnerable spot in Apple’s protection. Notarization is supposed to filter out dangerous applications, and the company assures that it checks them for malicious components. But ways to hide a virus from verification exist, and this is far from the first case when Apple has let dangerous applications through to users’ computers.
Signs of a Dangerous Application on Mac
The main defense here isn’t technology but vigilance. Two simple rules are enough to avoid falling for such a trick.
- The real crash reporting tool doesn’t require an administrator password to send a report. Moreover, you don’t need to download it. If an internet download pulls along a CrashReporter, that’s a warning sign.
- Be wary if an application asks for a password right at first launch. Especially when you’ve just downloaded it from a third-party site.
The logic is simple: almost any Mac malware sooner or later hits the need to obtain your password because macOS protection is built in multiple layers. Don’t enter your system password at the first request from an unfamiliar program, and half the problems will resolve themselves. If you’re unsure about the download source — simply don’t launch the application.
How Dangerous Are Viruses for Regular Mac Owners

Regularly update macOS and pay close attention to where and what applications you download
There’s definitely no need to panic. Apple has already blocked the specific infection path, and the attack itself, judging by the PIN code during installation, was targeted and unlikely to have affected regular users. But the lessons from it are useful for everyone. Those who store crypto wallet access on their Mac or passwords in managers like 1Password, LastPass, and Dashlane should be especially careful. That’s exactly the data the virus was hunting for. If you only download software from the App Store and from verified developer websites, your risk is minimal.
Don’t forget about updates either. Patches close vulnerabilities faster than any advice.