Skip to content
PamStealer: New macOS Infostealer Targets Users via Fake Maccy Manager

PamStealer: New macOS Infostealer Targets Users via Fake Maccy Manager

First seen 3 Jul 2026, 09:25 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •July 4, 2026 at 08:57 UTC
  • •PamStealer disguises itself as the legitimate Maccy clipboard manager to lure victims.
  • •The malware verifies login credentials through Apple's PAM before stealing data.
  • •PamStealer collects a wide range of sensitive information, including browser cookies and clipboard contents.

PamStealer is a newly identified macOS infostealer that masquerades as the legitimate Maccy clipboard manager. The malware employs a two-stage attack method, starting with a malicious AppleScript that downloads a Rust-based payload. It verifies Mac login passwords using Apple's Pluggable Authentication Modules (PAM) before stealing sensitive data, enhancing the effectiveness of stolen credentials. The attack vector involves a fraudulent website mimicking the official Maccy page, leading to the download of a malicious disk image. Once executed, PamStealer collects browser cookies, saved credentials, clipboard contents, and more, while also establishing persistence on the infected system. The malware's design incorporates social engineering tactics to convince users to enter their passwords. Jamf Threat Labs has documented this campaign, emphasizing its unique features compared to typical macOS infostealers.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 99d ago How this analysis works

Timeline

2026-07-02
PamStealer identified by Jamf Threat Labs
Researchers documented the new macOS infostealer that verifies passwords before data theft.
Appleinsider
2026-07-03
PamStealer attack method detailed
Jamf Threat Labs released findings on PamStealer's two-stage attack and its unique password verification feature.
www.jamf.com
2026-07-03
Malware uses social engineering tactics
PamStealer tricks users into entering their passwords by displaying a fake macOS authorization prompt.
Appleinsider

More articles in this cluster (86)

Following this threat?

Track ClickLock in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed