NEWS

PamStealer's Third Variant Adds Live C2 Payload Decryption and Four-Layer Persistence

Jamf Threat Labs found a third PamStealer variant tying payload decryption to a live X25519 exchange with its C2 server and four persistence layers.

Dylan H.

News Desk

September 28, 2026
9 min read
PamStealer's Third Variant Adds Live C2 Payload Decryption and Four-Layer Persistence

PamStealer Returns With a Server-Gated Payload and a Fake Crypto Wallet Lure

Jamf Threat Labs has identified a third known variant of PamStealer, the macOS infostealer family CosmicBytez Labs first covered in July 2026 when it impersonated the Maccy clipboard manager. According to researcher Thijs Xhaflaire, the new artifacts — published September 22, 2026 and reported by The Hacker News on September 25 — keep the family's signature JavaScript for Automation (JXA) dropper but add a server-side decryption chain: the second-stage payload is now unwrapped only after a live X25519 key exchange with the attacker's command-and-control (C2) infrastructure, meaning "without the server's cooperation, the payload cannot be recovered statically." The campaign also drops its earlier fake clipboard-manager lures for a new one — a bogus cryptocurrency wallet called "Wavel" distributed from wavel[.]app.


Incident Details

AttributeValue
Malware familyPamStealer (third known variant)
Discovered byJamf Threat Labs (researcher Thijs Xhaflaire)
Publication dateSeptember 22, 2026 (Jamf); September 25, 2026 (The Hacker News)
PlatformmacOS (Apple Silicon and Intel — FAT Mach-O binaries)
Delivery lureFake "Wavel" multichain crypto wallet at wavel[.]app
Prior lures (Jul–Aug 2026)Fake Maccy, Scoppr, and Nancy Clipboard sites
Dropper mechanismCompiled AppleScript (.scpt) → JXA → backgrounded zsh
Decryption utility"pkgunpack" (FAT Mach-O, arm64/x86_64)
CryptographyX25519 key exchange, AES-256-GCM, SHA-256 KDF
C2 domainwavel.apple03cloudstore[.]com
Secondary payload hosty32me8[.]com
Second-stage languageSwift (rewritten from Rust)
Persistence layers4 (LaunchAgent, repair script, zsh hook, Git hooks)
Credential validationPAM-based, retained from earlier variants

What Changed Since the July Campaign

A New Lure: The "Wavel" Crypto Wallet

Where the July variant impersonated Maccy — a legitimate open-source clipboard manager — to catch developers and technical users, this variant abandons clipboard-tool impersonation entirely in favor of a fake cryptocurrency wallet. Victims land on wavel[.]app, download a disk image containing Wavel.dmg, and open a compiled AppleScript file disguised as a generic document. Opening it launches Script Editor with instructions that trigger the embedded JXA code — the same delivery pattern used across all three known PamStealer variants, but now paired with a lure aimed squarely at cryptocurrency holders rather than developers and sysadmins.

Live, Server-Gated Payload Decryption

This is the headline change. In earlier variants, the decryption key material needed to unwrap the second-stage payload was embedded directly in the JXA source — meaning a captured sample could, in principle, be statically decrypted and analyzed offline. The new variant instead downloads a purpose-built utility called pkgunpack, which:

  1. Generates a fresh ephemeral X25519 keypair on every execution (genkey subcommand)
  2. Exchanges public keys with the C2 server, which holds a hardcoded server public key (I6VuXPzLJfPEXgVRO5ycNXdMWHWvMAkrLMV6OpEuwDw=)
  3. Derives a key-encryption key via SHA-256 with a domain separator string ("sn-dek-wrap-v1")
  4. Unwraps the data-encryption key (DEK) from a server-returned blob prefixed with the magic bytes SNWK1
  5. Decrypts the payload envelope (magic bytes SNP1) with AES-256-GCM

Because the keypair is regenerated on every run, a captured DEK-wrap response cannot be replayed against a different session — and because the private half of the exchange lives only on the attacker's server, a sample pulled from disk gives incident responders very little to work with. The decrypted archive expands to Wavel.app, which the dropper then renames to Finder.app to blend in as a system component.

Four Redundant Persistence Mechanisms

Where the July variant relied on standard persistence typical of macOS infostealers, this version installs four separate, mutually reinforcing mechanisms designed to survive partial cleanup:

#MechanismTrigger
1LaunchAgent (com.apple.finder.agent)Runs at login and re-checks every 15 seconds with crash recovery
2Repair script (.repair-run)Restores the app bundle and LaunchAgent from a local backup tarball (.sysnotif-backup.tgz) — works with no network contact
3Shell hook (appended to .zshrc)Fires every time the user opens an interactive zsh session
4Git hooks (post-checkout, pre-commit)Fires on routine git checkout or git commit activity

Before registering the LaunchAgent, the dropper also pauses BackgroundTaskManagementAgent, BTMNotificationAgent, and NotificationCenter so macOS does not alert the user that a new background login item was added. Deleting the visible fake app does not remove the infection — the repair layers simply restore it, and two of the four fire during ordinary daily use (opening a terminal, working in a Git repo).

Second-Stage Rewrite: Rust to Swift, PAM Validation Intact

The second-stage infostealer — internally named MacClient — has been rewritten from Rust to Swift, but its defining behavior carries over unchanged: it validates stolen passwords through macOS's PAM API via an exported _pam_verify_login function before exfiltrating them, ensuring the operators only receive confirmed, working credentials. The Swift binary also exports _kc_grab_storage_item (Keychain access) and _sqlite_backup_database (browser data), and presents the same two-stage deception: a fake macOS password prompt followed by a spoofed "damaged and can't be opened" Gatekeeper-style dialog.

Data collection has also broadened. The malware now targets 17 browsers by bundle ID — including Chrome (stable/Beta/Dev/Canary), Brave, Edge, Vivaldi, Opera/Opera GX, Firefox, Arc, Zen, Waterfox, LibreWolf, Yandex Browser, and CocCoc — spawning per-browser helper processes that impersonate the target browser to bypass macOS's cross-app authorization prompts. It also captures 21 system-fingerprint attributes via system_profiler, the user's Open Directory profile photo, shell history, .gitconfig, installed applications, and running processes, before assembling everything into a ZIP archive and exfiltrating it via a PUT request carrying a stable X-Upload-Token header.

Impact Assessment

Impact AreaDescription
Credential exposureAny credentials on an affected Mac — system password, Keychain items, browser-saved logins — should be treated as compromised; PAM validation means attackers receive only confirmed-working passwords
Forensic difficultyStatic payload decryption is no longer possible without a live C2 session; the useful evidence now lives on the host and in network traffic, not in the recovered file
Removal difficultyFour independent, partially network-independent persistence mechanisms mean deleting the visible app alone does not clean the host
Cryptocurrency holdersThe Wavel wallet lure specifically targets crypto users; wallet files and seed phrases copied to clipboard remain a theft target
Enterprise exposure17-browser coverage and system fingerprinting give operators broad visibility into corporate-managed Macs, not just personal-use browsers
Detection evasionNotification-center suppression during LaunchAgent registration means standard "new login item" alerts will not fire

Recommendations

For macOS Users

  1. Never install a crypto wallet, clipboard manager, or utility app from a disk image linked in an ad, search result, or unsolicited message. Go directly to the vendor's known-good domain or the Mac App Store.
  2. Treat any application that opens Script Editor and asks you to "run" or "follow instructions" as malicious. Legitimate macOS installers do not require you to execute AppleScript manually.
  3. Be suspicious of any password prompt that appears immediately after opening a downloaded app, especially one followed by a "damaged and can't be opened" message — this is PamStealer's known deception pattern.
  4. If you suspect infection, do not simply delete the app. Check for and remove all four persistence layers (below) before considering the host clean, and rotate every credential stored in Keychain or a browser.

For Security Teams and IT Admins

  1. Hunt for the four persistence artifacts on managed fleets:
    • LaunchAgent com.apple.finder.agent
    • ~/Library/Application Support/System/.repair-run and .sysnotif-backup.tgz
    • Unexpected append blocks in ~/.zshrc
    • post-checkout / pre-commit hooks under a non-standard core.hooksPath, or in ~/.git/hooks/
  2. Block network indicators: wavel[.]app, wavel.apple03cloudstore[.]com, and y32me8[.]com at DNS/proxy layers.
  3. Alert on Finder.app duplicates outside /System/ or /Applications/ — the dropper's masquerade renaming is a strong, low-noise detection signal.
  4. Monitor for suppression of BackgroundTaskManagementAgent / BTMNotificationAgent / NotificationCenter immediately preceding a new LaunchAgent registration — this sequence is unusual outside of MDM-managed deployments.
  5. Assume static analysis of a captured sample will be incomplete. Because the payload decryption key never touches disk, forensic response should prioritize live memory capture, network traffic (TLS metadata to the C2 domains), and EDR telemetry over the recovered binary alone.
  6. Rotate credentials fleet-wide for any Mac showing these indicators — PAM validation means stolen passwords are known-working, not guesses.

Key Takeaways

  1. This is PamStealer's third known variant, evolving from the July campaign (fake Maccy sites) and an August wave (Scoppr, Nancy Clipboard) to a September campaign impersonating a fake crypto wallet, "Wavel."
  2. Payload decryption now requires live C2 cooperation via an X25519 key exchange and AES-256-GCM unwrap — static analysis of a captured sample alone can no longer recover the second-stage payload.
  3. Persistence is now four layers deep, including a local backup tarball that survives with no network contact and Git hooks that re-trigger on routine developer activity.
  4. The second-stage stealer moved from Rust to Swift but kept its namesake PAM-based password validation, ensuring operators only receive confirmed-working credentials.
  5. Browser targeting expanded to 17 applications, and the malware now fingerprints 21 system attributes and extracts the user's Open Directory profile photo.
  6. Deleting the visible app does not remove the infection — defenders must locate and remove all four persistence mechanisms and rotate all credentials on any affected host.

Sources