
New macOS Infostealer CrashStealer Bypasses Gatekeeper Using Signed Apps
A new macOS infostealer named CrashStealer uses a signed application to bypass Gatekeeper security controls, enabling it to steal credentials and cryptocurrency wallets before AES-encrypting the stolen data. Jamf Threat Labs first identified the malware in early May 2026 after a suspicious macOS sample was uploaded to VirusTotal, with in-the-wild detections confirming active deployment by early July 2026. The malware targets macOS systems by leveraging signed apps to evade detection, though no specific CVE IDs or affected software versions were disclosed. Its primary impact includes unauthorized data exfiltration, particularly sensitive credentials and wallet information. No additional technical details about the encryption method or distribution vectors were provided.