You are currently viewing macOS Infostealers: CrashStealer and ClickLock Stealer

macOS Infostealers: CrashStealer and ClickLock Stealer

Jamf Threat Labs tracked CrashStealer, macOS malware disguised as Apple’s crash reporter, stealing browser credentials, crypto wallets, and keychain data via AES-GCM encryption. Written in C++, it spreads via a signed dropper (Werkbit) first seen on VirusTotal in May 2026. Separately, Group-IB found ClickLock Stealer, which tricks users into pasting a malicious Terminal command. Active for months, it hit 33 countries (mostly Europe). Both reports include IOCs and protection tips like never pasting unknown Terminal commands and responding if your Mac unexpectedly asks for a password. For more information https://www.jamf.com/blog/crashstealer-macos-infostealer-analysis/