Cybersecurity researchers have flagged a new version of PamStealer that ensures that the main payload can only be recovered using a server-side decryption chain.
The latest artifacts, per Jamf Threat Labs, continue to rely on the same JavaScript for Automation (JXA) dropper mechanism, but modify the lure and the delivery method.
"Where earlier variants embedded their payload key material
Ravie LakshmananSep 25, 2026Malware / Social Engineering
Cybersecurity researchers have flagged a new version of PamStealer that ensures that the main payload can only be recovered using a server-side decryption chain.
The latest artifacts, per Jamf Threat Labs, continue to rely on the same JavaScript for Automation (JXA) dropper mechanism, but modify the lure and the delivery method.
"Where earlier variants embedded their payload key material directly in the JXA source, it now fetches a purpose-built decryption utility and completes a key exchange with the server before the payload can be unwrapped," security researcher Thijs Xhaflaire said in an analysis. "Without the server's cooperation, the payload cannot be recovered statically."
A second major change is the choice of the decoy itself. While previous versions observed in July and August 2026 were observed using fake websites masquerading as Maccy, Scoppr, and Nancy Clipboard, victims are now lured through a bogus website ("wavel[.]app") advertising a non-existent cryptocurrency wallet service named Wavel.
Clicking the "Download for macOS" button on the fake site leads to the retrieval of a disk image file ("Wavel.dmg") that contains a compiled AppleScript file. Opening the file launches Apple's built-in Script Editor with instructions to trigger the execution of a JXA dropper.
"In Maccy, Scoppr and Nancy, the JXA source performed RC4 decryption of an embedded payload, made Objective-C framework calls through JXA's bridge to Foundation and NSData, and managed the entire download and staging process," Xhaflaire explained.
"In Wavel, the JXA source contains none of that. The entire JXA layer is now a carrier. When Script Editor executes the file, it decodes the base64 string and pipes the result into /bin/zsh -s, where zsh reads and executes the decoded bytes from standard input. The JXA process exits immediately; the zsh dropper continues in the background."
The decoded zsh script is takes the infection forward by carrying out the following actions -
Because the server holds the private key that completes the key exchange process, the Data Encryption Key (DEK) cannot be recovered without it, thereby preventing the payload from being decrypted. Furthermore, given that a new ephemeral keypair is generated during every execution, a captured DEK value cannot be replayed to extract the contents of the payload.
This, in turn, renders the encrypted payload effectively useless for static analysis without access to a live command-and-control (C2) session.
![]() |
| Ephemeral key generation and a live DEK exchange |
What's more, the repair script is copied to "post-checkout" and "pre-commit" folders within "~/Library/Application Support/System/.githooks/," with the Git configuration option "git config --global core.hooksPath" set to the directory. As a result, any git checkout or git commit action in any repository on the compromised system will silently activate the repair script.
The final stage is the stealer component written in Swift, marking a departure from the predecessor, which was implemented in Rust. Despite the change in the programming language used, the end goal is the same -
"The inclusion of Arc, Zen and the less common regional and privacy-focused browsers extends the target list noticeably beyond what is typical in commodity macOS stealers," Xhaflaire said.
"This variant of PamStealer reflects a deliberate investment in delivery infrastructure. The pkgunpack utility introduces a live key exchange that ties payload decryption to server availability: without C2 cooperation, the second stage cannot be decrypted. That design makes static recovery of the payload significantly harder and shifts part of the operational control to the server operator."
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
| # | Наименование новости | Тональность | Информативность | Дата публикации |
|---|---|---|---|---|
| 1 | MacSync macOS Stealer Returns With Binary Payloads and iCloud Tricks | 0 | 13 | 25-09-2026 |
| 2 | Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials | 0 | 12.32 | 26-09-2026 |
| 3 | Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets | 0 | 9.2 | 30-09-2026 |
| 4 | Apple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks | 0 | 6.97 | 28-09-2026 |
| 5 | 101 Malicious npm Packages Add Developers' WhatsApp Accounts to Groups Without Consent | 0 | 7.18 | 29-09-2026 |
| 6 | New Spectre-v2 BTR Attack Leaks Linux Memory Despite Existing Defenses | 0 | 9.23 | 29-09-2026 |
| 7 | Малварь ToxicPanda злоупотребляет VPN-механизмом Android, чтобы блокировать доступ к Google Play | 0 | 13.04 | 28-08-2026 |
| 8 | Carbonato Botnet Compromises Docker Hosts to Deploy Telegram-Controlled Hermes AI Agent | 0 | 8.54 | 28-09-2026 |
| 9 | Citrix Netscaler: Kritische Sicherheitslücken erlauben Codeeinschleusung | 0 | 9.03 | 27-09-2026 |