Story perspectives
Jamf: PamStealer Poses as Maccy, Hijacks Mac Credentials
7/3/2026
1 of 1
Story summary
- Jamf Threat Labs reports PamStealer disguises as the Maccy manager and uses an attack to steal data.
- The malware is delivered from sites that mimic maccy.app and provide disk images.
- A JavaScript downloader fetches a Rust payload that pretends to be Finder, encrypts traffic, and delays prompts forty minutes.
- PamStealer validates the password via PAM before harvesting credentials, prompting Jamf to recommend trusted sources or the Mac App Store.
