| Hi A new Mac-targeting malware strain, dubbed CrashStealer, has been spotted disguising itself as Apple's built-in crash-reporting tool. Its installer is signed and even Apple-notarized, so it slips right past the security warnings a normal Mac would show for untrusted software. Because it's built to look clean on the surface, we want to focus this alert on the behavior pattern to recognize — not just the malware's name or file signature, which the attackers can change at will. The behavior pattern, step by step | | A gated download. Victims land on a fake software page and are asked to enter a “meeting PIN” before they're allowed to download anything — a classic trick to keep the bait limited to targeted people. | | | | A disguised install. The installer quietly sets itself up under a name that mimics Apple's own crash reporter and creates a background helper process so it survives a restart. | | | | A fake permission prompt. Shortly after, a password box pops up that looks like a normal macOS system request. It's actually the malware trying to unlock your Mac's Keychain — the vault holding saved website logins, Wi-Fi passwords, and app tokens. | | | | Quiet, ongoing collection. Once it has your password, it copies browser logins, crypto wallet data, and password manager vaults, encrypts everything, and sends it out in the background — no warning, no visible sign anything happened. | | What this means for you | ✓ The password prompt is the red flag — not the file name. If a Keychain or admin password box pops up right after installing new software, stop and don't type anything in. | | ✓ “PIN-gated” downloads are a lure. Legitimate software doesn't require a code to unlock a download link — that's a sign the offer is targeted bait, not a normal release. | | ✓ Looking “official” isn't proof of safety. This malware passed Apple's own signing and notarization checks, so a clean-looking installer or icon doesn't mean it's trustworthy. | | ✓ Crypto wallets and password managers are prime targets. If your team uses tools like MetaMask, Phantom, 1Password, or Bitwarden on a Mac, treat any unexpected related prompt with extra suspicion right now. | | | Source: BleepingComputer · “New CrashStealer malware poses as Apple crash reporting tool,” July 13, 2026 | | Seen something similar? If a Mac on your team downloaded software recently from an unfamiliar site, or got a surprise password prompt, submit a ticket and we'll check it out before anything leaves the building. ✉ Submit a ticket Time-sensitive? Call the helpdesk: 541.696.5555 · Option 1 | When in doubt about a download or an unexpected prompt, pause before you click “Allow.” A quick check with us costs nothing — cleaning up a stolen Keychain does. |