The CrashStealer macOS malware shows how attackers are abusing trusted-looking system prompts to steal sensitive data from Mac users.

CrashStealer pretends to be Apple’s crash-reporting tool and uses fake password prompts to trick users into entering their macOS credentials. Once it has access, it can steal browser data, Keychain information, cryptocurrency wallet data, files, and other sensitive material.

The malware has reportedly been distributed through a notarized app, which makes the attack more convincing because users may assume that Apple notarization means the app is fully safe. In reality, notarization reduces some risk, but it does not guarantee that an application is trustworthy forever. Apparently, even a digital approval sticker can still be wrapped around a bad idea.

This is especially serious for businesses using Mac devices for development, finance, executive work, design, or cryptocurrency operations. A stolen Keychain, browser session, or wallet seed can lead to account takeover, cloud compromise, financial theft, and further phishing.

Users should avoid installing apps from unknown sources, verify software publishers, and treat unexpected password prompts with suspicion. Organizations should monitor for unusual access to Keychain data, suspicious app execution, unexpected login items, abnormal outbound connections, and attempts to collect browser or wallet data.

The key lesson is that macOS is not immune to infostealers. Attackers no longer need to break the operating system if they can convince the user to approve the theft through a realistic-looking system prompt.


A new macOS information-stealing malware called CrashStealer pretends to be Apple's crash-reporting tool to steal credentials, keychain data, and crypto wallets. [...]

Source: New CrashStealer malware poses as Apple crash reporting tool via Bleeping Computer — published 13 Jul 2026.