Dangerous new CrashStealer Mac impersonates Apple's own tools  and bypasses Gatekeeper  to steal your passwords and more 70%

By Anthony Spadafora86%

7/15/2026, 12:35:38 PM

BS Summary: This article contains 25 faulty reasoning types, including Ambiguity (Equivocation), Loss Aversion, and Indoctrination, with Negativity Bias as the most egregious example at 39.7% saturation with 319 hits. Analysis detected 1,997 faulty-reasoning hits from 804 analyzed words, generating a BS Score of 62.6% and a BS Rank of 70% (6,739 of 21,887 articles). This article is worse (more manipulative) than 69.20% of the article peer group.

Even with one of the best MacBooks , you can never be too careful when downloading new apps. 
Case in point: a new malicious Mac app is posing as a legitimate Apple tool to steal passwords, keychain data and more from vulnerable systems. 
As reported by BleepingComputer , the app in question serves as a means to infect vulnerable Apple computers with a new Mac info-stealer . 
While security researchers at Jamf first observed it back in May when it was still in development, this malware is now being actively used by cybercriminals in their attacks. 
Dubbed CrashStealer, what makes this Mac malware strain so dangerous is the way in which it perfectly mimics Apple’s own macOS crash reports. 
Although something might seem off to more discerning users, others could easily fall for this attack given how much care and attention has gone into impersonating this legitimate tool. 
Here’s everything you need to know about this new Mac malware and how you can keep your own MacBook and all the sensitive data it contains safe from hackers. 
Impersonating a legitimate Apple utility 
In their report , Jamf’s security researchers explain how the malware hides in plain sight by posing as a meeting platform called Werkbit. 
While they don’t go into details about the malware’s initial distribution method, a malicious app like this could be distributed via fake ads or on a developer-focused site like GitHub. 
After downloading the app, it’s mounted on your desktop just like with any new software you download for your Mac. 
Surprisingly, though, the hackers behind this campaign are using a signed and Apple-notarized installer to distribute their fake app. 
Not only does this add a sense of legitimacy to the app but it also allows it to bypass Apple’s built-in Gatekeeper security feature without any warnings whatsoever. 
When launched for the first time, the app displays a fake macOS password prompt that looks strikingly similar to what you’d see when downloading new software manually as opposed to through the Mac App Store. 
Once a victim puts in the password for their Mac, the hackers then have everything they need to unlock their Apple Keychain which acts as macOS’ encrypted password vault and contains all sorts of sensitive info like saved credentials in Safari, app passwords, Wi-Fi passwords and more. 
The CrashStealer malware isn’t just limited to stealing from your Keychain though. 
It can also steal browser credentials and cookies from Chrome and other Chromium-based browsers as well as Firefox. 
Likewise, it can steal data from 80 different crypto wallet extensions and 14 of the best password managers including 1Password, LastPass, Dashlane and more. 
To get all of this stolen data off your Mac, the malware encrypts it before packaging it into hidden ZIP archives and uploading it to a hacker-controlled C&C server. 
By using a signed and notarized dropper and a re-signed payload, CrashStealer is a sophisticated Mac malware that’s especially good at avoiding detection. 
How to stay safe from Mac malware 
(Image credit: robert coolen/Shutterstock) If you’re worried about CrashStealer and other Mac malware, the first thing you should do is to avoid sideloading apps, or in this case, installing new apps from anywhere besides the Mac App Store . 
Just like on one of the best Android smartphones , when you download new apps from websites instead of an official app store, you’re putting your devices and the data they contain at risk. 
Apps submitted to the Mac App Store go through rigorous security checks while those you download from a random website don’t. 
Normally when you download an unverified app from the web, macOS’s built-in Gatekeeper security feature will block it or warn you before you install it. 
In this case, though, that doesn’t happen since the installer used in this campaign is signed and appears to be legitimate. 
Well, at least in Gatekeeper’s eyes. 
While Gatekeeper can keep you safe from most threats, there are ones like this that manage to bypass its defenses. 
For this reason, you might want to consider using one of the best Mac antivirus software solutions alongside Apple’s built-in ones. 
That way, if something slips past Apple, your third-party antivirus software will be able to stop the threat before it can do serious damage. 
Since CrashStealer is still a relatively new Mac malware, this likely won’t be the last time we see it. 
This is why you always need to be extra careful when downloading and installing new software onto your Apple computer. 
More from Tom’s Guide 
New PamStealer Mac malware poses as a clipboard manager to steal login info 
Apple’s ‘Hide My Email’ reportedly exposing real email addresses 
GTA 6 warning: Pre-order scams are stealing users' info and spreading malware 
Article reasoning-pattern comparisonThis article: 2.6%Anthony Spadafora: 0.7%Tomsguide: 2.9%Confirmation Bias2.6%This article: 2.4%Anthony Spadafora: 0.6%Tomsguide: 1.5%Anchoring Bias2.4%This article: 13.3%Anthony Spadafora: 5.0%Tomsguide: 3.1%Availability Heuristic13.3%This article: 13.9%Anthony Spadafora: 3.5%Tomsguide: 1.1%Representativeness Heuristic13.9%This article: 0.0%Anthony Spadafora: 0.0%Tomsguide: 0.3%Hindsight Bias0.0%This article: 6.7%Anthony Spadafora: 2.4%Tomsguide: 3.6%Overconfidence Bias6.7%This article: 10.7%Anthony Spadafora: 6.1%Tomsguide: 4.6%Framing Effect10.7%This article: 18.0%Anthony Spadafora: 9.5%Tomsguide: 1.6%Loss Aversion18.0%This article: 5.7%Anthony Spadafora: 1.4%Tomsguide: 0.7%Status Quo Bias5.7%This article: 0.0%Anthony Spadafora: 0.0%Tomsguide: 0.2%Sunk Cost Effect0.0%This article: 5.6%Anthony Spadafora: 1.4%Tomsguide: 4.9%Optimism Bias5.6%This article: 8.2%Anthony Spadafora: 4.4%Tomsguide: 1.3%Pessimism Bias8.2%This article: 39.7%Anthony Spadafora: 19.1%Tomsguide: 4.0%Negativity Bias39.7%This article: 0.0%Anthony Spadafora: 0.0%Tomsguide: 1.2%Self-Serving Bias0.0%This article: 0.0%Anthony Spadafora: 0.0%Tomsguide: 0.3%Fundamental Attribution Error0.0%This article: 0.0%Anthony Spadafora: 0.0%Tomsguide: 0.1%Actor-Observer Bias0.0%This article: 0.0%Anthony Spadafora: 0.0%Tomsguide: 0.4%In-Group Bias0.0%This article: 0.0%Anthony Spadafora: 0.0%Tomsguide: 0.1%Out-Group Homogeneity Bias0.0%This article: 2.9%Anthony Spadafora: 1.6%Tomsguide: 5.3%Halo Effect2.9%This article: 0.0%Anthony Spadafora: 0.0%Tomsguide: 0.1%Horn Effect0.0%This article: 0.0%Anthony Spadafora: 0.0%Tomsguide: 0.0%Dunning-Kruger Effect0.0%This article: 7.6%Anthony Spadafora: 2.8%Tomsguide: 1.2%Recency Bias7.6%This article: 0.0%Anthony Spadafora: 0.0%Tomsguide: 0.5%Primacy Effect0.0%This article: 0.0%Anthony Spadafora: 0.0%Tomsguide: 0.1%Blind-Spot Bias0.0%This article: 0.0%Anthony Spadafora: 0.0%Tomsguide: 0.0%Ad Hominem0.0%This article: 0.0%Anthony Spadafora: 0.0%Tomsguide: 0.0%Straw Man0.0%This article: 5.8%Anthony Spadafora: 2.9%Tomsguide: 3.8%Appeal to Authority5.8%This article: 10.0%Anthony Spadafora: 5.4%Tomsguide: 1.6%False Dilemma10.0%This article: 2.4%Anthony Spadafora: 0.6%Tomsguide: 0.2%Slippery Slope2.4%This article: 0.0%Anthony Spadafora: 0.0%Tomsguide: 0.3%Circular Reasoning0.0%This article: 15.3%Anthony Spadafora: 8.6%Tomsguide: 5.2%Hasty Generalization15.3%This article: 0.0%Anthony Spadafora: 0.0%Tomsguide: 0.1%Red Herring0.0%This article: 0.0%Anthony Spadafora: 0.0%Tomsguide: 0.9%Bandwagon0.0%This article: 4.1%Anthony Spadafora: 4.6%Tomsguide: 3.6%Appeal to Emotion4.1%This article: 0.0%Anthony Spadafora: 0.0%Tomsguide: 0.5%Begging the Question0.0%This article: 15.0%Anthony Spadafora: 3.8%Tomsguide: 1.3%Post Hoc (False Cause)15.0%This article: 0.0%Anthony Spadafora: 0.0%Tomsguide: 0.2%Tu Quoque0.0%This article: 0.0%Anthony Spadafora: 0.0%Tomsguide: 0.3%Burden of Proof0.0%This article: 0.0%Anthony Spadafora: 0.0%Tomsguide: 0.1%Appeal to Nature0.0%This article: 4.2%Anthony Spadafora: 1.1%Tomsguide: 0.1%Composition/Division4.2%This article: 1.1%Anthony Spadafora: 0.3%Tomsguide: 2.7%Anecdotal1.1%This article: 0.0%Anthony Spadafora: 0.0%Tomsguide: 0.0%No True Scotsman0.0%This article: 23.0%Anthony Spadafora: 5.8%Tomsguide: 2.6%Ambiguity (Equivocation)23.0%This article: 0.0%Anthony Spadafora: 0.0%Tomsguide: 0.0%Gambler’s Fallacy0.0%This article: 0.0%Anthony Spadafora: 0.0%Tomsguide: 0.1%Middle Ground0.0%This article: 0.0%Anthony Spadafora: 0.0%Tomsguide: 0.1%Personal Incredulity0.0%This article: 0.0%Anthony Spadafora: 0.0%Tomsguide: 0.2%Special Pleading0.0%This article: 0.0%Anthony Spadafora: 0.0%Tomsguide: 0.0%Genetic Fallacy0.0%This article: 0.0%Anthony Spadafora: 0.0%Tomsguide: 1.4%Unattributed Quote0.0%This article: 0.0%Anthony Spadafora: 0.0%Tomsguide: 0.4%Quote-first Misdirection0.0%This article: 6.5%Anthony Spadafora: 4.1%Tomsguide: 12.4%Biased Writer Voice6.5%This article: 16.2%Anthony Spadafora: 13.8%Tomsguide: 4.2%Indoctrination16.2%This article: 0.0%Anthony Spadafora: 0.0%Tomsguide: 0.0%Politically Left Leaning Bias0.0%This article: 0.0%Anthony Spadafora: 0.0%Tomsguide: 0.0%Politically Right Leaning Bias0.0%This article: 7.5%Anthony Spadafora: 6.1%Tomsguide: 14.0%Attempt to Sell a Product or S…7.5%

804 words analyzed.

Speakers

2speakers9.5%attributed speech728writer words
Voice mapSelect a segment to jump to its words
Writer's voice • 19 words • 100.0% coverageWriter's voice • 18 words • 100.0% coverageWriter's voice • 25 words • 0.0% coverageBleepingComputer • 24 words • 0.0% coverageJamf • 29 words • 0.0% coverageWriter's voice • 23 words • 0.0% coverageWriter's voice • 29 words • 0.0% coverageWriter's voice • 29 words • 100.0% coverageWriter's voice • 5 words • 0.0% coverageJamf • 23 words • 0.0% coverageWriter's voice • 30 words • 0.0% coverageWriter's voice • 20 words • 0.0% coverageWriter's voice • 19 words • 0.0% coverageWriter's voice • 28 words • 0.0% coverageWriter's voice • 35 words • 0.0% coverageWriter's voice • 47 words • 0.0% coverageWriter's voice • 12 words • 0.0% coverageWriter's voice • 18 words • 0.0% coverageWriter's voice • 24 words • 0.0% coverageWriter's voice • 29 words • 0.0% coverageWriter's voice • 23 words • 0.0% coverageWriter's voice • 7 words • 0.0% coverageWriter's voice • 39 words • 100.0% coverageWriter's voice • 34 words • 0.0% coverageWriter's voice • 21 words • 0.0% coverageWriter's voice • 25 words • 0.0% coverageWriter's voice • 21 words • 0.0% coverageWriter's voice • 6 words • 0.0% coverageWriter's voice • 20 words • 0.0% coverageWriter's voice • 21 words • 100.0% coverageWriter's voice • 24 words • 100.0% coverageWriter's voice • 19 words • 0.0% coverageWriter's voice • 20 words • 100.0% coverageWriter's voice • 4 words • 0.0% coverageWriter's voice • 13 words • 0.0% coverageWriter's voice • 9 words • 0.0% coverageWriter's voice • 12 words • 100.0% coverage
Selected voice

Jamf

100%flagged-word coverage
52 attributed words68% of attributed speech98% writer coverage
0%10.0%20.0%Indoctrination-17.9 ptsWriter: 17.9%Jamf: 0.0%0.0%Attempt to Sell a Product -8.2 ptsWriter: 8.2%Jamf: 0.0%0.0%Biased Writer Voice-7.1 ptsWriter: 7.1%Jamf: 0.0%0.0%

Attribution is sentence-level. Pattern percentages are calculated only from words assigned to that voice.

Loading…
Loading…
Loading…
Loading…

Analysis

Hover over highlighted words in the article to view the associated bias or fallacy analysis.