Get free scan and check if your device is infected.
Remove it nowTo use full-featured product, you have to purchase a license for Combo Cleaner. Seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
What kind of malware is CrashStealer Malware?
CrashStealer Malware is an information stealer targeting macOS users, discovered by Jamf Threat Labs in May 2026. It disguises itself as Apple's native crash-reporting tool to blend in with legitimate macOS processes.
CrashStealer targets saved passwords, Keychain entries, browser cookies, and data from around 80 cryptocurrency wallet extensions. It also collects data from popular password managers and sends everything it gathers to an attacker-controlled server. If CrashStealer Malware is detected on a device, it should be removed immediately.

CrashStealer Malware overview
According to research by Jamf Threat Labs, CrashStealer arrives on a Mac through a two-stage infection chain. In the first stage, the victim receives a disk image named Werkbit Setup that is signed and Apple-notarized under a valid developer certificate.
Because this installer carries a valid certificate, macOS's Gatekeeper security feature does not block it. Once the Werkbit installer runs, it silently contacts a remote server to fetch a shell script. That script downloads the actual malware payload, a disk image named CrashReporter.dmg.
The payload is copied to a hidden directory, stripped of its original code signature, and re-signed before being launched. The malware then presents itself as Apple's crash-reporting component, using the bundle ID com.apple.crashreporter and matching icons to look like a legitimate system process.
What CrashStealer Malware steals
Before collecting any data, the malware displays a fake macOS password prompt. If the user enters their password, the stealer validates it locally and uses it to unlock the Mac's Keychain, gaining access to stored credentials including Safari logins, Wi-Fi passwords, and cryptographic keys.
CrashStealer targets saved passwords, cookies, and browsing data from Chrome, Brave, Edge, Opera, Opera GX, Vivaldi, NAVER Whale, Firefox, and Safari. It also searches around 80 cryptocurrency wallet browser extensions, including MetaMask, Phantom, Coinbase Wallet, Trust Wallet, Rabby, OKX Wallet, Exodus, Solflare, and Backpack.
Additionally, it targets 14 password manager applications, including 1Password, Bitwarden, LastPass, Dashlane, Keeper, KeePassXC, NordPass, Enpass, and RoboForm. CrashStealer also performs a recursive file search through the user's Desktop, Documents, and Downloads folders.
Persistence and defense evasion
CrashStealer installs a LaunchAgent named com.apple.crashreporter.helper that automatically restarts the malware whenever the Mac is started or the user logs in. The agent is configured to relaunch the stealer if the process exits, maintaining persistent access to the system.
To avoid detection, the malware strips its own code signature and replaces it with an ad-hoc one, changing the file hash so that hash-based security tools cannot recognize it. It also checks for a debugger at startup and exits immediately if one is found.
Strings inside the binary, such as the command-and-control server address and browser target paths, are stored in encrypted form. Stolen data is packed into hidden ZIP archives before being uploaded, and the staging directory uses an Apple-style name to avoid standing out.
| Name | CrashStealer virus |
| Threat Type | Mac malware, Mac virus, stealer, password-stealing virus. |
| Symptoms | Stealers are designed to stealthily infiltrate the victim's computer and remain silent, and thus no particular symptoms are clearly visible on an infected machine. |
| Distribution Methods | Signed and notarized fake installer (Werkbit Setup), social engineering, malicious disk image, targeted delivery. |
| Detection Names | Avast (MacOS:Agent-BOC [Trj]), Combo Cleaner (Trojan.MAC.Downloader.51), ESET-NOD32 (OSX/TrojanDownloader.Agent.CV Trojan), Kaspersky (UDS:Trojan-Downloader.OSX.Agent), Full List Of Detections (VirusTotal) |
| Damage | Stolen passwords and banking information, identity theft, financial loss, possible additional infections. |
| Malware Removal (Windows) |
To eliminate possible malware infections, scan your computer with legitimate antivirus software. Our security researchers recommend using Combo Cleaner. Download Combo CleanerTo use full-featured product, you have to purchase a license for Combo Cleaner. 7 days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com. |
Conclusion
CrashStealer Malware is a sophisticated Mac stealer that can capture saved passwords, Keychain credentials, cryptocurrency wallet data, and password manager information, all while posing as a legitimate Apple component.
Its client-side encryption and code-signature manipulation make it harder to detect than many commodity stealers. In summary, infections of this kind can result in severe privacy issues, significant financial losses, and identity theft. If there is reason to believe a Mac is infected, CrashStealer should be removed immediately.
Some examples of information stealers targeting macOS are ClickLock, ShadeStager, and Infiniti.
How did CrashStealer Malware infiltrate my device?
As documented by Jamf Threat Labs, CrashStealer is distributed through a signed and Apple-notarized disk image called Werkbit Setup, hosted on a fake software website at werkbit[.]io. Because the installer carries a valid Apple developer certificate, it passes Gatekeeper's checks without triggering security warnings.
When the Werkbit installer runs, it silently contacts a remote server to fetch a shell script, which then downloads and installs the actual malware payload disguised as Apple's crash-reporting component. Access to the download link was protected by a meeting PIN, suggesting the campaign targeted specific individuals rather than distributing the malware broadly.
More broadly, macOS malware is also spread through phishing emails with malicious attachments, fake software download sites, software "cracks" and pirated applications, and social engineering tricks that lead users to install something they believe is legitimate.
How to avoid malware?
Be cautious about files received through unexpected messages, emails, or pop-ups. Only download software from official sources such as the Mac App Store or verified developer websites, and avoid pirated programs, key generators, and unofficial mirrors. Keep macOS and all installed applications updated regularly.
Be wary of prompts asking for your system password, especially from applications you did not intentionally launch. If your computer is already infected, we recommend running a scan with Combo Cleaner Antivirus for Windows to automatically eliminate all threats.
Werkbit Setup disk image used to distribute CrashStealer Malware (source: jamf.com):

Instant automatic malware removal:
Manual threat removal might be a lengthy and complicated process that requires advanced IT skills. Combo Cleaner is a professional automatic malware removal tool that is recommended to get rid of malware. Download it by clicking the button below:
DOWNLOAD Combo CleanerBy downloading any software listed on this website you agree to our Privacy Policy and Terms of Use. To use full-featured product, you have to purchase a license for Combo Cleaner. 7 days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Quick menu:
Potentially unwanted applications removal:
Remove potentially unwanted applications from your "Applications" folder:

Click the Finder icon. In the Finder window, select "Applications". In the applications folder, look for "MPlayerX","NicePlayer", or other suspicious applications and drag them to the Trash. After removing the potentially unwanted application(s) that cause online ads, scan your Mac for any remaining unwanted components.
DOWNLOAD remover for malware infections
Combo Cleaner checks if your computer is infected with malware. To use full-featured product, you have to purchase a license for Combo Cleaner. 7 days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Frequently Asked Questions (FAQ)
My device is infected with CrashStealer Malware, should I format my storage device to get rid of it?
A full system format can remove CrashStealer Malware, but it will also erase all data stored on the device. Because of this, it is usually better to first attempt removal using a trusted security tool like Combo Cleaner.
What are the biggest issues that CrashStealer Malware can cause?
CrashStealer is designed to steal sensitive information, including passwords, Keychain entries, cryptocurrency wallet data, and password manager contents. Infections of this kind can lead to severe privacy issues, financial losses, and identity theft.
What is the purpose of CrashStealer Malware?
The purpose of CrashStealer Malware is to steal sensitive data from infected macOS devices, including saved passwords, browser credentials, Keychain contents, and cryptocurrency wallet information, then send it to an attacker-controlled server.
How did CrashStealer Malware infiltrate my computer?
CrashStealer typically gets on a Mac through a signed and notarized fake installer called Werkbit Setup. Because this installer carries a valid Apple developer certificate, it bypasses Gatekeeper and installs without triggering security warnings. Access was further limited by a PIN, indicating a targeted campaign.
Will Combo Cleaner protect me from malware?
Yes, Combo Cleaner can detect and remove most threats. However, more advanced threats can be well hidden in the system, so it is important to run a full scan to ensure elimination.
Share:
Tomas Meskauskas
Expert security researcher, professional malware analyst
I am passionate about computer security and technology. I have an experience of over 10 years working in various companies related to computer technical issue solving and Internet security. I have been working as an author and editor for pcrisk.com since 2010. Follow me on Twitter and LinkedIn to stay informed about the latest online security threats.
PCrisk security portal is brought by a company RCS LT.
Joined forces of security researchers help educate computer users about the latest online security threats. More information about the company RCS LT.
Our malware removal guides are free. However, if you want to support us you can send us a donation.
DonatePCrisk security portal is brought by a company RCS LT.
Joined forces of security researchers help educate computer users about the latest online security threats. More information about the company RCS LT.
Our malware removal guides are free. However, if you want to support us you can send us a donation.
Donate
▼ Show Discussion