Jamf Threat Labs has uncovered a new piece of macOS malware called CrashStealer. It targets 80 different crypto wallet extensions and 14 password managers, and it manages to bypass Apple's Gatekeeper security feature. The discovery raises fresh concerns about the security of crypto assets on Mac machines.
What CrashStealer targets
The malware is laser-focused on credentials. According to Jamf's findings, CrashStealer goes after browser extensions tied to nearly every major crypto wallet — including MetaMask, Phantom, and others. It also scrapes data from popular password managers like 1Password and LastPass. That combination makes it a potent tool for stealing both private keys and login details.
How it gets around Gatekeeper
Apple's Gatekeeper is meant to block unsigned or untrusted software from running. But CrashStealer finds a way through. Jamf's researchers say the malware uses a technique that sidesteps the usual checks, allowing it to execute on a victim's machine without triggering the system's warnings. Exactly how it does that hasn't been fully detailed yet, but the bypass is the core of the threat.
Discovery and what's next
Jamf Threat Labs identified CrashStealer as part of its ongoing macOS threat monitoring. The firm hasn't said how the malware is being distributed — whether through fake downloads, phishing links, or something else. That question remains open. For now, Mac users running crypto wallets are on notice: a new credential-stealing tool is in the wild, and it's designed to evade one of Apple's key defenses.




