logo

PamStealer: a Rust-based macOS infostealer that validates credentials through PAM

ID: 37462adb-b8c9-570d-89fa-b7486f5abe35

STIX ID: report--37462adb-b8c9-570d-89fa-b7486f5abe35

Feed Name: Jamf Blog

Threat Score
75/100

Date Published: 2026-07-01

Date Updated: 2026-07-16

...
...

PamStealer is a macOS-focused infostealer delivered via a Script Editor (.scpt) JXA dropper that stages a Rust arm64 Mach-O. The dropper performs environment- and region-aware checks, ad-hoc signs and launches a staged bundle masquerading as Finder or Software Update; the second-stage steals browser credential databases, clipboard contents, and validated login passwords via a PAM-backed fake authorization prompt, attempts to coerce Full Disk Access via a counterfeit system dialog, persists through login item APIs (both modern and legacy) including an embedded helper, and exfiltrates data to an encrypted Cloudflare-fronted C2 (notably avenger-sync.live) using ChaCha20-Poly1305; analysis artifacts and caches provide actionable IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.