malware
Published 2026-09-22
Verified 2026-09-27

PamStealer Wavel (Jamf 22 Sep): fake macOS crypto-wallet installer; Swift stage + server-side ECIES decrypt

Jamf Threat Labs (22 September 2026) documents a third PamStealer macOS infostealer variant distributed as a fake multichain crypto wallet “Wavel”. Lure site wavel[.]app serves Wavel.dmg from y32me8[.]com; the DMG drops a nameless .scpt that opens in Script Editor and runs compiled JXA (JsOsaDAS1.001.00 magic) which only base64-decodes a carrier into /bin/zsh. The zsh dropper downloads a purpose-built pkgunpack Mach-O, completes a live X25519/ECIES key exchange with wavel.apple03cloudstore[.]com, and decrypts CoreUpdate.pkg.enc — without server cooperation the payload cannot be recovered statically. Stage 2 is rewritten from Rust to Swift while retaining PAM-based credential validation that names the family. Distinct from desk Rapuncel LastPass SEO lure. Primary: Jamf Threat Labs; wire: Cyber Security News 23 Sep 2026.

Product
macOS endpoints (PamStealer infostealer family — Wavel variant)
Versions
n/a (malware campaign; third known PamStealer variant after Maccy/Scoppr/Nancy-style JXA lures)
Exploited in Australia?
unknown
Patch to
Block/monitor wavel[.]app, y32me8[.]com, wavel.apple03cloudstore[.]com; alert on Script Editor launching zsh/base64 pipelines and ad-hoc codesign of /tmp/.pkgunpack-*; hunt Jamf IoCs; user education against fake wallet DMG/.scpt installers

Primary: Jamf Threat Labs — PamStealer adapts again (Wavel / Swift / server-side decrypt, 22 Sep 2026) · Vendor: Jamf — PamStealer Wavel analysis · Cyber Security News — PamStealer fake crypto wallet (23 Sep 2026 wire)

tech australia identity