{"id":2335,"date":"2026-07-06T00:38:45","date_gmt":"2026-07-06T00:38:45","guid":{"rendered":"https:\/\/xrpfaucet.site\/?p=2335"},"modified":"2026-07-06T00:38:45","modified_gmt":"2026-07-06T00:38:45","slug":"fake-mac-clipboard-app-delivers-new-password-stealing-malware","status":"publish","type":"post","link":"https:\/\/xrpfaucet.site\/?p=2335","title":{"rendered":"Fake Mac Clipboard App Delivers New Password-Stealing Malware"},"content":{"rendered":"<div class=\"crypto-article\">\n<p>\ud83d\udcf0 <strong>Exclusive Crypto News &#038; Analysis:<\/strong> Stay ahead with the latest developments in the cryptocurrency and blockchain space.<\/p>\n<p>\ud83d\udcc8 <strong>Market Update:<\/strong> Real-time price movements, technical analysis, and trading signals.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/img.decrypt.co\/insecure\/rs:fill:1024:512:1:0\/plain\/https:\/\/cdn.decrypt.co\/wp-content\/uploads\/2025\/08\/crime_hacker-gID_7.png@png\" \/><\/p>\n<div style=\"position:relative;overflow:visible;font-size:1.2em;line-height:1.58\">\n<div class=\"pt-8 pb-10 border-t border-b border-decryptGridline \">\n<h4 class=\"sc-b2a202e4-4 bNRGqr gg-dark:text-white\" color=\"#333\">In brief<\/h4>\n<ul>\n<li class=\"font-meta-serif-pro font-normal text-lg md:text-xl md:leading-9 tracking-px text-body gg-dark:text-neutral-100\">Jamf Threat Labs identified a new Rust-based macOS infostealer posing as the Maccy clipboard manager.<\/li>\n<li class=\"font-meta-serif-pro font-normal text-lg md:text-xl md:leading-9 tracking-px text-body gg-dark:text-neutral-100\">The malware validates victims&#8217; passwords through macOS PAM before stealing them.<\/li>\n<li class=\"font-meta-serif-pro font-normal text-lg md:text-xl md:leading-9 tracking-px text-body gg-dark:text-neutral-100\">Researchers also spotted ClickFix-style malware delivered through a sponsored advertisement on X.<\/li>\n<\/ul>\n<\/div>\n<p class=\"font-meta-serif-pro scene:font-noto-sans scene:text-base scene:md:text-lg font-normal text-lg md:text-xl md:leading-9 tracking-px text-body gg-dark:text-neutral-100\">Mac users searching for the open-source clipboard manager Maccy are being targeted by a fake version of the app that installs a new Rust-based infostealer dubbed PamStealer, according to cybersecurity firm Jamf Threat Labs. If successful, the malware could steal users\u2019 passwords and crypto wallet keys.<\/p>\n<p class=\"font-meta-serif-pro scene:font-noto-sans scene:text-base scene:md:text-lg font-normal text-lg md:text-xl md:leading-9 tracking-px text-body gg-dark:text-neutral-100\">In a <a href=\"https:\/\/www.jamf.com\/blog\/pamstealer-macos-infostealer-applescript-rust\/\" target=\"_blank\" rel=\"noopener nofollow external\" class=\"sc-adb616fe-0 bJsyml\">report<\/a> published on Thursday, Jamf Threat Labs said the campaign uses a lookalike website to distribute a disk image containing a malicious AppleScript file named Maccy.scpt. When opened, the file displays instructions telling users to run it in Apple&#8217;s Script Editor while hiding the malicious code further down the document.<\/p>\n<p class=\"font-meta-serif-pro scene:font-noto-sans scene:text-base scene:md:text-lg font-normal text-lg md:text-xl md:leading-9 tracking-px text-body gg-dark:text-neutral-100\">\u201cWe are tracking this malware under the name PamStealer after one of its core behaviors: validating the victim\u2019s login password through the macOS Pluggable Authentication Modules (PAM) before harvesting it,\u201d Jamf Threat Labs wrote.<\/p>\n<p class=\"font-meta-serif-pro scene:font-noto-sans scene:text-base scene:md:text-lg font-normal text-lg md:text-xl md:leading-9 tracking-px text-body gg-dark:text-neutral-100\">From there, the malware uses JavaScript for Automation and native macOS APIs to download a second-stage payload without relying on common shell utilities such as curl or zsh, reducing the number of processes security tools can observe.<\/p>\n<p><iframe loading=\"lazy\" style=\"border:0\" src=\"https:\/\/myriad.markets\/embed\/market\/btc-next-move-pump-to-84k-or-dump-to-55k-3d262902-135d-416e-90bc-8e80233f341e\" width=\"100%\" height=\"415px\"><span data-mce-type=\"bookmark\" style=\"display:inline-block;width:0px;overflow:hidden;line-height:0\" class=\"mce_SELRES_start\">\ufeff<\/span><\/iframe><\/p>\n<p class=\"font-meta-serif-pro scene:font-noto-sans scene:text-base scene:md:text-lg font-normal text-lg md:text-xl md:leading-9 tracking-px text-body gg-dark:text-neutral-100\">&#8220;With many stealers, we have seen attackers purchasing Google Ad space to lure users to the malicious app. We have recently observed malicious ads being hosted on X as well,\u201d Jamf Threat Labs Director Jaron Bradley told <i>Decrypt<\/i>. \u201cThese social engineering techniques have proven to be highly successful.&#8221;<\/p>\n<p class=\"font-meta-serif-pro scene:font-noto-sans scene:text-base scene:md:text-lg font-normal text-lg md:text-xl md:leading-9 tracking-px text-body gg-dark:text-neutral-100\">According to the report, the second stage is a Rust-based binary designed for Apple Silicon Macs that disguises itself as Finder or Software Update.<\/p>\n<p class=\"font-meta-serif-pro scene:font-noto-sans scene:text-base scene:md:text-lg font-normal text-lg md:text-xl md:leading-9 tracking-px text-body gg-dark:text-neutral-100\">\u201cRather than storing its configuration in cleartext, the dropper derives a key from a fingerprint of the host\u2014including its CPU architecture, locale, keyboard layout, and time zone\u2014and uses it to unlock an encrypted, integrity-checked configuration containing the payload URL and installation path,\u201d the company said.<\/p>\n<p class=\"font-meta-serif-pro scene:font-noto-sans scene:text-base scene:md:text-lg font-normal text-lg md:text-xl md:leading-9 tracking-px text-body gg-dark:text-neutral-100\">Once installed, the malware can steal browser credentials and Keychain data, monitor clipboard contents, establish persistence, and send stolen information to a remote command-and-control server using encrypted communications. If it can&#8217;t verify that it&#8217;s running on its intended target, then it quietly shuts itself down.<\/p>\n<p class=\"font-meta-serif-pro scene:font-noto-sans scene:text-base scene:md:text-lg font-normal text-lg md:text-xl md:leading-9 tracking-px text-body gg-dark:text-neutral-100\">The malware also attempts to expand its access by displaying a fake Finder alert asking users to grant Full Disk Access. The prompt can appear up to 40 minutes after infection, making it less likely that users will associate it with the original download. If approved, the malware can access protected data, including Mail, Messages, and Time Machine backups.<\/p>\n<p class=\"font-meta-serif-pro scene:font-noto-sans scene:text-base scene:md:text-lg font-normal text-lg md:text-xl md:leading-9 tracking-px text-body gg-dark:text-neutral-100\">According to Bradley, Jamf has not observed any evidence that PamStealer is active in the wild; however, the company notified Apple of its findings. Apple did not immediately respond to a request for comment by <i>Decrypt.<\/i><\/p>\n<p class=\"font-meta-serif-pro scene:font-noto-sans scene:text-base scene:md:text-lg font-normal text-lg md:text-xl md:leading-9 tracking-px text-body gg-dark:text-neutral-100\"><span style=\"font-weight:400\">Jamf said it is seeing similar social engineering techniques spread to other platforms. <\/span><\/p>\n<p class=\"font-meta-serif-pro scene:font-noto-sans scene:text-base scene:md:text-lg font-normal text-lg md:text-xl md:leading-9 tracking-px text-body gg-dark:text-neutral-100\"><span style=\"font-weight:400\">In an <\/span><a href=\"https:\/\/x.com\/JamfThreatLabs\/status\/2071600199126970563?s=20\" target=\"_blank\" rel=\"noopener nofollow external\" class=\"sc-adb616fe-0 bJsyml\"><span style=\"font-weight:400\">X post<\/span><\/a><span style=\"font-weight:400\">  last week, the company said it was investigating a sponsored advertisement on X promoting DynamicLake that redirected users to dynamicmacisland(.)com, where they were instructed to open Terminal and execute an installation command.<\/span><\/p>\n<p class=\"font-meta-serif-pro scene:font-noto-sans scene:text-base scene:md:text-lg font-normal text-lg md:text-xl md:leading-9 tracking-px text-body gg-dark:text-neutral-100\"><span style=\"font-weight:400\">\u201cThe advertisement was delivered through a verified X account, adding another layer of trust to the social engineering,\u201d the firm wrote. \u201cAnalysis of the payload revealed a recent Atomic (MacSync) Stealer variant.\u201d<\/span><\/p>\n<p class=\"font-meta-serif-pro scene:font-noto-sans scene:text-base scene:md:text-lg font-normal text-lg md:text-xl md:leading-9 tracking-px text-body gg-dark:text-neutral-100\">The findings come as attackers increasingly disguise malware as legitimate software and abuse trusted developer platforms and advertising channels. Recent campaigns have included a fake OpenAI <a href=\"https:\/\/decrypt.co\/367659\/fake-openai-repo-hugging-face-stole-passwords\" target=\"_blank\" rel=\"noopener\" class=\"sc-adb616fe-0 bJsyml\">repository<\/a> that reached the top of Hugging Face&#8217;s trending projects before distributing a Rust-based infostealer, a malicious Visual Studio Code extension that GitHub said exposed roughly <a href=\"https:\/\/decrypt.co\/368476\/github-confirms-3800-internal-repos-stolen-poisoned-vs-code-extension\" target=\"_blank\" rel=\"noopener\" class=\"sc-adb616fe-0 bJsyml\">3,800<\/a> internal repositories, and the <a href=\"https:\/\/decrypt.co\/368477\/shai-hulud-what-know-malware-spreading-software-pipelines\" target=\"_blank\" rel=\"noopener\" class=\"sc-adb616fe-0 bJsyml\">Shai-Hulud<\/a> software supply-chain campaign targeting development tools used by AI companies including <a href=\"https:\/\/decrypt.co\/367883\/openai-confirms-security-breach-ai-malware-campaign\" target=\"_blank\" rel=\"noopener\" class=\"sc-adb616fe-0 bJsyml\">OpenAI<\/a> and Mistral AI.<\/p>\n<div class=\"my-4 border-b border-decryptGridline\">\n<div class=\"text-start p-8 md:py-12 md:px-12 max-w-prose relative\"><span class=\"border-t-4 border-l-4 w-4 h-4 md:border-t-(6px) md:border-l-(6px) md:w-6 md:h-6 border-decryptPurple dark:border-decryptNeon gg-dark:border-cc-pink-2 absolute top-4 left-4 md:top-6 md:left-6\"\/><span class=\"border-t-4 border-l-4 w-4 h-4 md:border-t-(6px) md:border-l-(6px) md:w-6 md:h-6 border-decryptPurple dark:border-decryptNeon gg-dark:border-cc-pink-2 absolute rotate-180 bottom-4 right-4 md:bottom-6 md:right-6\"\/><\/p>\n<h3 class=\"font-akzidenz-grotesk font-bold text-xl md:text-3xl md:text-center gg-dark:text-white\">Daily Debrief<!-- --> Newsletter<\/h3>\n<p>Start every day with the top news stories right now, plus original features, a podcast, videos and more.<\/p>\n<\/div>\n<\/div>\n<\/div>\n<p>\ud83d\udca1 <strong>Pro Tip:<\/strong> Bookmark our site for daily insights, market predictions, and expert trading strategies.<\/p>\n<p>\ud83d\udd17 <strong>Explore More:<\/strong> Check our sections for in-depth guides, exchange reviews, and blockchain technology deep-dives.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ud83d\udcf0 Exclusive Crypto News &#038; Analysis: Stay ahead with the latest developments in the cryptocurrency and blockchain space. \ud83d\udcc8 Market Update: Real-time price movements, technical analysis, and trading signals. In brief Jamf Threat Labs identified a new Rust-based macOS infostealer posing as the Maccy clipboard manager. The malware validates victims&#8217; passwords through macOS PAM before &hellip;<\/p>\n","protected":false},"author":1,"featured_media":2336,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_seopress_titles_title":"","_seopress_titles_desc":"","_seopress_robots_index":"","_seopress_robots_follow":"","_seopress_robots_imageindex":"","_seopress_robots_snippet":"","_seopress_robots_primary_cat":"","_seopress_robots_breadcrumbs":"","_seopress_robots_freeze_modified_date":"","_seopress_robots_custom_modified_date":"","_seopress_robots_canonical":"","_seopress_social_fb_title":"","_seopress_social_fb_desc":"","_seopress_social_fb_img":"","_seopress_social_fb_img_attachment_id":0,"_seopress_social_fb_img_width":0,"_seopress_social_fb_img_height":0,"_seopress_social_twitter_title":"","_seopress_social_twitter_desc":"","_seopress_social_twitter_img":"","_seopress_social_twitter_img_attachment_id":0,"_seopress_social_twitter_img_width":0,"_seopress_social_twitter_img_height":0,"_seopress_redirections_value":"","_seopress_redirections_enabled":"","_seopress_redirections_enabled_regex":"","_seopress_redirections_logged_status":"","_seopress_redirections_param":"","_seopress_redirections_type":0,"_seopress_analysis_target_kw":"","footnotes":""},"categories":[10],"tags":[],"class_list":["post-2335","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/xrpfaucet.site\/index.php?rest_route=\/wp\/v2\/posts\/2335","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/xrpfaucet.site\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/xrpfaucet.site\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/xrpfaucet.site\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/xrpfaucet.site\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2335"}],"version-history":[{"count":0,"href":"https:\/\/xrpfaucet.site\/index.php?rest_route=\/wp\/v2\/posts\/2335\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/xrpfaucet.site\/index.php?rest_route=\/wp\/v2\/media\/2336"}],"wp:attachment":[{"href":"https:\/\/xrpfaucet.site\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2335"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/xrpfaucet.site\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2335"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/xrpfaucet.site\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2335"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}