CrashStealer macOS Malware Uses Notarized Dropper to Pass Gatekeeper Checks 13%

By Ravie Lakshmanan12%

7/13/2026, 10:36:00 AM

BS Summary: This article contains 15 faulty reasoning types, including Unattributed Quote, Framing Effect, and Anecdotal, with Ambiguity (Equivocation) as the most egregious example at 14.5% saturation with 74 hits. Analysis detected 483 faulty-reasoning hits from 510 analyzed words, generating a BS Score of 29.2% and a BS Rank of 13% (19,225 of 21,887 articles). This article is better (less manipulative) than 87.80% of the article peer group.

Cybersecurity researchers have flagged a new macOS information stealer called CrashStealer that's capable of harvesting sensitive data from compromised systems. 
Unlike other information stealers that are built on AppleScript droppers or Objective-C-based wrappers, CrashStealer is implemented in native C++, according to Jamf Threat Labs. 
"It validates the victim's login password locally before harvesting, collects broadly across browsers, cryptocurrency wallets, password managers, and the keychain, encrypts what it collects with AES-GCM before exfiltrating over libcurl, and persists by copying and re-signing itself," security researcher Thijs Xhaflaire said in a report shared with The Hacker News. 
CrashStealer is said to be distributed by means of a signed and Apple-notarized dropper that's distributed as a disk image file named "Werkbit.app." 
Because both the disk image and binary are notarized and carry a valid developer ID ("Emil Grigorov (WWB7JA7AQV)"), it passes Gatekeeper checks. 
The disk image itself originates from the domain "werkbit[.]io," which was registered in June 2026. 
In an interesting twist, the download is gated behind a meeting PIN, meaning the installer is served only to those site visitors who arrive with the right code rather than everyone. 
The discovery of additional domains and shared backend infrastructure tied to the same operation points to CrashStealer being part of a larger, multi-platform campaign. 
Once mounted, the disk image presents the user with an installation setup screen that instructs them to right-click the app and choose "Open" to get them to run it. 
Once launched, the "veltod" executable contacts a GitHub repository ("github.com/mgothiclove") to retrieve a file named "sys.cache." 
The file is then used to extract a curl command and pull a shell script, which acts as a downloader to fetch and stage the next payload ("CrashReporter.dmg") and saves it to the "/tmp" directory. 
The malware, upon execution, establishes persistence as a LaunchAgent, resists analysis, presents a password prompt and validates the entered credential locally, unlocks the login keychain using the validated password, lists installed security and analysis tooling, before proceeding to collect browser data, cryptocurrency wallet extensions, password manager data, and keychain material. 
The complete list of data harvested is below - 
Credentials from Chromium-family browsers, including Google Chrome, Brave, Microsoft Edge, Opera and Opera GX, Vivaldi, Chromium, and Naver Whale 
Roughly 80 cryptocurrency wallet extensions, including MetaMask, Phantom, Coinbase, Trust Wallet, Rabby, OKX Wallet, Exodus, Keplr, Solflare, and Backpack 
14 password managers, including 1Password, Bitwarden, LastPass, Dashlane, Keeper, KeePassXC, NordPass, Enpass and RoboForm 
File from ~/Documents and ~/Downloads directories 
The harvested data is then packaged into a ZIP archive and exfiltrated to an attacker-controlled server ("179.43.166[.] 
242"). 
"CrashStealer's delivery chain shows real care: rather than a bare, unsigned lure, the operators front the attack with a signed and notarized dropper that clears Gatekeeper before quietly fetching, re-signing and launching the payload," Jamf said. 
"What sets it apart from the commodity stealer crowd is less what it collects than how it is built: client-side AES-GCM encryption of the collected files, and an emphasis on analysis resistance through control-flow flattening, encrypted strings and layered anti-debugging." 
Article reasoning-pattern comparisonThis article: 0.0%Ravie Lakshmanan: 1.5%The Hacker News: 1.9%Confirmation Bias0.0%This article: 0.0%Ravie Lakshmanan: 1.4%The Hacker News: 1.2%Anchoring Bias0.0%This article: 3.7%Ravie Lakshmanan: 2.4%The Hacker News: 3.3%Availability Heuristic3.7%This article: 0.0%Ravie Lakshmanan: 1.7%The Hacker News: 1.5%Representativeness Heuristic0.0%This article: 4.7%Ravie Lakshmanan: 0.9%The Hacker News: 0.6%Hindsight Bias4.7%This article: 1.8%Ravie Lakshmanan: 2.4%The Hacker News: 2.5%Overconfidence Bias1.8%This article: 7.8%Ravie Lakshmanan: 2.4%The Hacker News: 2.7%Framing Effect7.8%This article: 0.0%Ravie Lakshmanan: 0.8%The Hacker News: 1.0%Loss Aversion0.0%This article: 0.0%Ravie Lakshmanan: 0.4%The Hacker News: 0.6%Status Quo Bias0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.1%Sunk Cost Effect0.0%This article: 0.0%Ravie Lakshmanan: 1.1%The Hacker News: 1.3%Optimism Bias0.0%This article: 0.0%Ravie Lakshmanan: 1.5%The Hacker News: 1.6%Pessimism Bias0.0%This article: 7.1%Ravie Lakshmanan: 7.7%The Hacker News: 6.7%Negativity Bias7.1%This article: 0.0%Ravie Lakshmanan: 0.3%The Hacker News: 0.8%Self-Serving Bias0.0%This article: 0.0%Ravie Lakshmanan: 0.6%The Hacker News: 0.4%Fundamental Attribution Error0.0%This article: 0.0%Ravie Lakshmanan: 0.1%The Hacker News: 0.1%Actor-Observer Bias0.0%This article: 0.0%Ravie Lakshmanan: 0.1%The Hacker News: 0.1%In-Group Bias0.0%This article: 0.0%Ravie Lakshmanan: 1.2%The Hacker News: 0.3%Out-Group Homogeneity Bias0.0%This article: 0.0%Ravie Lakshmanan: 0.3%The Hacker News: 0.6%Halo Effect0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.0%Horn Effect0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.0%Dunning-Kruger Effect0.0%This article: 0.0%Ravie Lakshmanan: 2.4%The Hacker News: 1.5%Recency Bias0.0%This article: 0.0%Ravie Lakshmanan: 0.3%The Hacker News: 0.3%Primacy Effect0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.1%Blind-Spot Bias0.0%This article: 0.0%Ravie Lakshmanan: 0.2%The Hacker News: 0.1%Ad Hominem0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.1%Straw Man0.0%This article: 4.7%Ravie Lakshmanan: 4.9%The Hacker News: 4.0%Appeal to Authority4.7%This article: 0.0%Ravie Lakshmanan: 0.5%The Hacker News: 1.6%False Dilemma0.0%This article: 0.0%Ravie Lakshmanan: 0.5%The Hacker News: 0.5%Slippery Slope0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.1%Circular Reasoning0.0%This article: 4.7%Ravie Lakshmanan: 4.0%The Hacker News: 4.3%Hasty Generalization4.7%This article: 0.0%Ravie Lakshmanan: 0.2%The Hacker News: 0.1%Red Herring0.0%This article: 0.0%Ravie Lakshmanan: 0.2%The Hacker News: 0.2%Bandwagon0.0%This article: 7.1%Ravie Lakshmanan: 1.1%The Hacker News: 1.1%Appeal to Emotion7.1%This article: 0.0%Ravie Lakshmanan: 0.2%The Hacker News: 0.5%Begging the Question0.0%This article: 4.3%Ravie Lakshmanan: 2.1%The Hacker News: 1.9%Post Hoc (False Cause)4.3%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.0%Tu Quoque0.0%This article: 1.8%Ravie Lakshmanan: 0.9%The Hacker News: 0.6%Burden of Proof1.8%This article: 0.0%Ravie Lakshmanan: 0.1%The Hacker News: 0.1%Appeal to Nature0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.3%Composition/Division0.0%This article: 7.8%Ravie Lakshmanan: 0.4%The Hacker News: 1.0%Anecdotal7.8%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.1%No True Scotsman0.0%This article: 14.5%Ravie Lakshmanan: 3.8%The Hacker News: 2.3%Ambiguity (Equivocation)14.5%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.0%Gambler’s Fallacy0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.0%Middle Ground0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.0%Personal Incredulity0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.1%Special Pleading0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.1%Genetic Fallacy0.0%This article: 9.8%Ravie Lakshmanan: 3.4%The Hacker News: 1.4%Unattributed Quote9.8%This article: 7.1%Ravie Lakshmanan: 2.6%The Hacker News: 0.9%Quote-first Misdirection7.1%This article: 7.8%Ravie Lakshmanan: 2.5%The Hacker News: 2.3%Biased Writer Voice7.8%This article: 0.0%Ravie Lakshmanan: 2.4%The Hacker News: 4.4%Indoctrination0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.0%Politically Left Leaning Bias0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.0%Politically Right Leaning Bias0.0%This article: 0.0%Ravie Lakshmanan: 0.4%The Hacker News: 3.0%Attempt to Sell a Product or S…0.0%

510 words analyzed.

Speakers

3speakers22%attributed speech400writer words
Voice mapSelect a segment to jump to its words
Writer's voice • 10 words • 0.0% coverageWriter's voice • 20 words • 0.0% coverageJamf Threat Labs • 24 words • 0.0% coverageThijs Xhaflaire • 50 words • 100.0% coverageWriter's voice • 23 words • 0.0% coverageWriter's voice • 22 words • 0.0% coverageWriter's voice • 15 words • 0.0% coverageWriter's voice • 31 words • 0.0% coverageWriter's voice • 24 words • 0.0% coverageWriter's voice • 29 words • 0.0% coverageWriter's voice • 16 words • 0.0% coverageWriter's voice • 35 words • 0.0% coverageWriter's voice • 50 words • 0.0% coverageWriter's voice • 9 words • 0.0% coverageWriter's voice • 19 words • 0.0% coverageWriter's voice • 19 words • 0.0% coverageWriter's voice • 14 words • 0.0% coverageWriter's voice • 6 words • 0.0% coverageWriter's voice • 17 words • 0.0% coverageWriter's voice • 1 words • 0.0% coverageJamf • 36 words • 100.0% coverageWriter's voice • 40 words • 100.0% coverage
Selected voice

Jamf

100%flagged-word coverage
36 attributed words33% of attributed speech42% writer coverage
0%50.0%100.0%Quote-first Misdirection+100.0 ptsWriter: 0.0%Jamf: 100.0%100.0%Biased Writer Voice-10.0 ptsWriter: 10.0%Jamf: 0.0%0.0%

Attribution is sentence-level. Pattern percentages are calculated only from words assigned to that voice.

Loading…
Loading…
Loading…
Loading…

Analysis

Hover over highlighted words in the article to view the associated bias or fallacy analysis.