
PamStealer macOS Variant Shifts to Server-Side X25519 Decryption and Four-Layer Persistence
PamStealer now requires live C2 interaction for payload decryption via X25519 and deploys redundant Git, LaunchAgent, and shell-hook persistence. The shift from embedded keys to server-held material blocks static analysis and replay attacks. This pattern indicates maturing operational security by the operators.
Jamf Threat Labs documented the September 2026 sample delivered via a fake Wavel cryptocurrency wallet site. The JXA dropper now only launches a zsh stub that fetches the pkgunpack utility, performs the ephemeral key exchange, and installs the payload. Four persistence mechanisms were observed: LaunchAgent, a repair zsh script, ~/.zshrc hook, and Git core.hooksPath pointing to ~/Library/Application Support/System/.githooks/. The Swift stealer targets PAM credentials, keychain items, and browser data. Earlier July-August variants embedded RC4 keys directly; the new design eliminates that static weakness. The change aligns with observed macOS malware trends toward runtime C2 dependency to frustrate sandbox detonation and reverse engineering. Git hook persistence is novel in this family and expands the attack surface for developers. Independent confirmation from multiple samples shows consistent use of the same four persistence vectors across victims.
Jamf Threat Labs: Within 90 days a new PamStealer sample will appear using a different browser engine for credential theft, detected via increased Git hook anomalies in enterprise telemetry.
Sources (2)
- [1]Primary Source(https://thehackernews.com/2026/09/pamstealer-macos-malware-adds-live-c2.html)
- [2]Supporting Source(https://www.jamf.com/blog/pamstealer-analysis-2026/)