Overview
- Jamf first flagged suspicious macOS samples in May 2026, and by mid‑July detailed findings from researchers led Apple to revoke the developer certificate used to distribute the dropper.
- The initial lure is a stapled, notarized disk image called Werkbit Setup that carries a valid Apple Developer ID and a gated download behind a meeting PIN so the installer runs without Gatekeeper warnings.
- When launched, the malware shows a native‑looking password dialog, verifies the password locally with the dscl tool, caches it, and uses it to unlock and copy the user’s login keychain.
- CrashStealer harvests browser credentials, cookies, about 80 crypto wallet extensions, 14 password managers and user files, encrypts each item with AES‑256‑GCM, hides results in .zx_*.zip archives, and persists by re‑signing a copy and installing a LaunchAgent named com.apple.crashreporter.helper.
- Researchers warn the campaign remains active with hardened infrastructure and cross‑platform indicators, so any Mac that ran the installer and had a password entered should be treated as compromised and disconnected, have credentials rotated, and be inspected or rebuilt following published IoCs and remediation guidance.