{"id":1113,"date":"2026-08-19T16:30:17","date_gmt":"2026-08-19T11:00:17","guid":{"rendered":"https:\/\/www.hexnode.com\/threat-watch\/?p=1113"},"modified":"2026-08-19T19:56:33","modified_gmt":"2026-08-19T14:26:33","slug":"crashstealer-macos-infostealer-keychain-endpoint-risk","status":"publish","type":"post","link":"https:\/\/www.hexnode.com\/threat-watch\/crashstealer-macos-infostealer-keychain-endpoint-risk\/","title":{"rendered":"CrashStealer macOS Malware: Fake Apple CrashReporter Steals Credentials"},"content":{"rendered":"<p>A new macOS infostealer called CrashStealer is masquerading as Apple&#8217;s crash reporting utility to steal high-value credentials and sensitive data from compromised Macs. By targeting Keychain secrets, browser credentials, password managers, cryptocurrency wallets, and local files, the malware aims to capture the identities, authentication artifacts, and business data that attackers can leverage for broader enterprise compromise.<\/p>\n<p>For organizations that manage macOS fleets, the campaign highlights a familiar challenge: legitimate-looking software and trusted installation mechanisms can reduce user suspicion while increasing the likelihood of credential theft. As attackers continue to focus on identity and endpoint data instead of destructive payloads, security teams need visibility into suspicious endpoint behavior alongside strong device and access controls to reduce the impact of a compromised workstation.<\/p>\n<h2>How CrashStealer Compromises macOS Systems<\/h2>\n<p>CrashStealer is engineered to resemble a legitimate macOS component to reduce suspicion during execution. The malware is distributed as an application bundle named CrashReporter.app, uses Apple-like iconography and metadata, and creates a LaunchAgent named com.apple.crashreporter.helper to blend in with legitimate system processes.<\/p>\n<p>The first-stage Werkbit Setup installer was digitally signed and Apple-notarized, allowing it to pass Gatekeeper&#8217;s initial trust checks without the unidentified-developer warning that users typically see for untrusted software. After execution, CrashStealer displays a fake macOS password prompt and validates the entered password locally using the dscl command-line utility before attempting to access protected data.<\/p>\n<p>Once credentials are validated, the malware collects data from multiple sources, including:<\/p>\n<ul>\n<li>Apple Keychain secrets<\/li>\n<li>Browser credentials and session cookies<\/li>\n<li>Password manager artifacts<\/li>\n<li>More than 80 cryptocurrency wallet extensions<\/li>\n<li>Files stored in user directories<\/li>\n<\/ul>\n<p>Before exfiltration, CrashStealer encrypts the stolen data using AES-256-GCM, packages it into hidden ZIP archives, and uploads it to attacker-controlled infrastructure through libcurl. This combination of trusted distribution, credential harvesting, encrypted staging, and stealthy data exfiltration makes the malware particularly effective against enterprise macOS environments.<br \/>\n<div class=\"next_blog\"><div class=\"post-next\"><div class=\"hex_blog_box_parent\"><div class=\"blog_warp_next\"><div class=\"next_blog_thumb\" style=\"background-image:url(https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Identity-provider-setup.webp?format=webp)\"><\/div><div class=\"next_post_content\"><div class=\"center_box\"><h4>Identity Provider Setup: What IT Teams Should Know Before Deployment<\/h4><p>Plan a secure identity provider setup with SSO, MFA, modern authentication, and device-aware access using Hexnode.<\/p><\/div><\/div><\/div><a class=\"hex_blog_box_link hn-cta__blogs--blog-box\" href=\"https:\/\/www.hexnode.com\/blogs\/identity-provider-setup-it-teams-guide\/\" aria-label=\"Identity Provider Setup: What IT Teams Should Know Before Deployment\"><\/a><\/div><\/div><\/div><\/p>\n<h2>How Hexnode Helps Reduce the Risk<\/h2>\n<p>A layered security approach can limit both the likelihood and impact of credential-stealing malware such as CrashStealer. <a href=\"https:\/\/www.hexnode.com\/uem\/\" rel=\"noopener\">Hexnode UEM<\/a> helps IT teams strengthen macOS security by enforcing OS updates, FileVault encryption, device compliance policies, and application control through allowlisting and blocklisting. These controls help reduce exposure to unauthorized software and ensure corporate Macs adhere to security baselines.<\/p>\n<p><a href=\"https:\/\/www.hexnode.com\/xdr\/\" rel=\"noopener\">Hexnode XDR<\/a> and endpoint security capabilities can complement these preventive controls by helping security teams identify suspicious endpoint behavior, including:<\/p>\n<ul>\n<li>LaunchAgent persistence indicative of unauthorized software.<\/li>\n<li>Unusual process execution that deviates from expected application behavior.<\/li>\n<li>Credential access attempts targeting sensitive data stores.<\/li>\n<li>Hidden archive creation that may indicate data staging before exfiltration.<\/li>\n<li>Suspicious outbound network activity consistent with data exfiltration attempts.<\/li>\n<\/ul>\n<p>When security teams identify malicious activity, Hexnode XDR\u2019s one-click remediation capabilities can help them respond quickly by:<\/p>\n<ul>\n<li><strong>Isolating the device<\/strong> to restrict network communication and help contain the threat.<\/li>\n<li><strong>Killing malicious processes<\/strong> to stop suspicious activity running on the endpoint.<\/li>\n<li><strong>Quarantining malicious files<\/strong> to prevent them from being accessed or executed.<\/li>\n<\/ul>\n<p>Organizations can combine Hexnode UEM, Hexnode XDR, and <a href=\"https:\/\/www.hexnode.com\/idp\/\" rel=\"noopener\">Hexnode IdP<\/a> to build layered defenses against identity-focused attacks. Hexnode IdP enables organizations to enforce identity-aware access policies so that only trusted, compliant devices can access sensitive applications and corporate resources. Even if attackers steal credentials or browser sessions, conditional access and device trust requirements can help reduce unauthorized access to business-critical resources.<br \/>\n<section id='resource-single'>\n                    <div class='resource-box'>\n                        <div class='resource-box__image-section'>\n                            <div class='resource-box__image-wrap'>\n                                <img decoding=\"async\" src=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/What-makes-Hexnode-the-go-to-UEM-vendor-in-the-market_Thumbnails-for-white-papers.webp?format=webp\" class=\"resource-box__image\" alt=\"What-makes-Hexnode-the-go-to-UEM-vendor-in-the-market_Thumbnails-for-white-papers\" loading=\"lazy\" srcset=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/What-makes-Hexnode-the-go-to-UEM-vendor-in-the-market_Thumbnails-for-white-papers.webp?format=webp 960w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/What-makes-Hexnode-the-go-to-UEM-vendor-in-the-market_Thumbnails-for-white-papers-300x225.webp?format=webp 300w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/What-makes-Hexnode-the-go-to-UEM-vendor-in-the-market_Thumbnails-for-white-papers-768x576.webp?format=webp 768w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/What-makes-Hexnode-the-go-to-UEM-vendor-in-the-market_Thumbnails-for-white-papers-133x100.webp?format=webp 133w\" sizes=\"auto, (max-width: 960px) 100vw, 960px\" title=\"What-makes-Hexnode-the-go-to-UEM-vendor-in-the-market_Thumbnails-for-white-papers\" \/>\n                            <\/div>\n                        <\/div>\n                        <div class='resource-box__content-section'>\n                            <h5 class='resource-box__content-subheading'>\n                            Featured Resource\n                            <\/h5>\n                            <h4 class='resource-box__content-heading'>\n                            What makes Hexnode the go-to UEM vendor in the market?\n                            <\/h4>\n                            <p class='resource-box__contents'>\n                            Download to learn why you should choose Hexnode when there are other vendors in the market claiming to be better than Hexnode.\n                            <\/p>\n                            <a class='resource-box__content-link hn-cta__blogs--resource-box' href='https:\/\/www.hexnode.com\/resources\/white-papers\/what-makes-hexnode-the-go-to-uem-vendor-in-the-market\/'>\n                            Get the Whitepaper\n                            <svg xmlns='http:\/\/www.w3.org\/2000\/svg' width='20' height='20' viewBox='0 0 20 20'>\n                            <g id='arrow' transform='translate(-309 -191)' opacity='0'>\n                                <rect id='base' width='20' height='20' transform='translate(309 191)' fill='none'\/>\n                                <path id='arrow-2' data-name='arrow' d='M13.093.5,6.8,6.8.5.5' transform='translate(315 207.594) rotate(-90)' fill='none' stroke='#0549d1' stroke-linecap='round' stroke-linejoin='round' stroke-width='1.2'\/>\n                            <\/g>\n                            <\/svg>\n\n                            <\/a>\n                        <\/div>\n                    <\/div>\n                <\/section><\/p>\n<h2>Conclusion<\/h2>\n<p>CrashStealer demonstrates that Apple notarization alone is not a guarantee of safety. Attackers can abuse trusted distribution mechanisms and convincing social engineering to deliver malware that targets enterprise credentials, session tokens, and other sensitive data. Security teams should evaluate software based on its behavior after execution, not just its installation trust signals.<\/p>\n<p>To reduce the risk from modern infostealers, organizations should combine application control, continuous endpoint monitoring, credential hygiene, and rapid incident response with UEM-enforced security baselines. A layered security strategy limits initial compromise, detects suspicious activity earlier, and contains threats before attackers can use stolen credentials to gain broader access across the enterprise.<br \/>\n<div class=\"signup_box\"><div class=\"signup_wrap_img\"><div class=\"signup-bg\" style=\"background-image:url(https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode-MDM-free-trial.jpg?format=webp)\"><\/div><\/div><div class=\"signup_wrap\"><h5>Try Hexnode free for 14 days<\/h5><p>Protect every endpoint before malware steals credentials. See how Hexnode secures enterprise devices.<\/p><a href=\"https:\/\/www.hexnode.com\/mobile-device-management\/cloud\/signup\/\" class=\"hn-cta__blogs--signup-stripe\" target=\"_blank\"> Sign Up Today<\/a><\/div><\/div><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A new macOS infostealer called CrashStealer is masquerading as Apple&#8217;s crash reporting utility to steal&#8230;<\/p>\n","protected":false},"author":8,"featured_media":1114,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[13,17],"class_list":["post-1113","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-identity-abuse","category-macos","product_category-extended-detection-and-response","tab_group-malware-and-ransomware"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>CrashStealer macOS Malware: Fake Apple CrashReporter Steals Credentials<\/title>\n<meta name=\"description\" content=\"CrashStealer macOS malware poses as Apple CrashReporter to steal Keychain, browser and password data. Learn XDR and UEM defenses.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.hexnode.com\/threat-watch\/crashstealer-macos-infostealer-keychain-endpoint-risk\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"CrashStealer macOS Malware: Fake Apple CrashReporter Steals Credentials\" \/>\n<meta property=\"og:description\" content=\"CrashStealer macOS malware poses as Apple CrashReporter to steal Keychain, browser and password data. Learn XDR and UEM defenses.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.hexnode.com\/threat-watch\/crashstealer-macos-infostealer-keychain-endpoint-risk\/\" \/>\n<meta property=\"og:site_name\" content=\"Hexnode Threat Watch\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Hexnode\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-08-19T11:00:17+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-19T14:26:33+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/CrashStealer-macOS-malware.webp?format=webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1024\" \/>\n\t<meta property=\"og:image:height\" content=\"535\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/webp\" \/>\n<meta name=\"author\" content=\"Alanna River\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:site\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Alanna River\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":[\"Article\",\"BlogPosting\"],\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/crashstealer-macos-infostealer-keychain-endpoint-risk\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/crashstealer-macos-infostealer-keychain-endpoint-risk\\\/\"},\"author\":{\"name\":\"Alanna River\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/c2ed050402be36f7ece23a9b07bc9e64\"},\"headline\":\"CrashStealer macOS Malware: Fake Apple CrashReporter Steals Credentials\",\"datePublished\":\"2026-08-19T11:00:17+00:00\",\"dateModified\":\"2026-08-19T14:26:33+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/crashstealer-macos-infostealer-keychain-endpoint-risk\\\/\"},\"wordCount\":663,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/crashstealer-macos-infostealer-keychain-endpoint-risk\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/CrashStealer-macOS-malware.webp?format=webp\",\"articleSection\":[\"Identity Abuse\",\"macOS\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/crashstealer-macos-infostealer-keychain-endpoint-risk\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/crashstealer-macos-infostealer-keychain-endpoint-risk\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/crashstealer-macos-infostealer-keychain-endpoint-risk\\\/\",\"name\":\"CrashStealer macOS Malware: Fake Apple CrashReporter Steals Credentials\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/crashstealer-macos-infostealer-keychain-endpoint-risk\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/crashstealer-macos-infostealer-keychain-endpoint-risk\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/CrashStealer-macOS-malware.webp?format=webp\",\"datePublished\":\"2026-08-19T11:00:17+00:00\",\"dateModified\":\"2026-08-19T14:26:33+00:00\",\"description\":\"CrashStealer macOS malware poses as Apple CrashReporter to steal Keychain, browser and password data. Learn XDR and UEM defenses.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/crashstealer-macos-infostealer-keychain-endpoint-risk\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/crashstealer-macos-infostealer-keychain-endpoint-risk\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/crashstealer-macos-infostealer-keychain-endpoint-risk\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/CrashStealer-macOS-malware.webp?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/CrashStealer-macOS-malware.webp?format=webp\",\"width\":1024,\"height\":535,\"caption\":\"CrashStealer-macOS-malware\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/crashstealer-macos-infostealer-keychain-endpoint-risk\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"CrashStealer macOS Malware: Fake Apple CrashReporter Steals Credentials\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"name\":\"Hexnode Threat Watch\",\"description\":\"Latest cyber threats, smarter enterprise response.\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"alternateName\":\"Threat Watch\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\",\"name\":\"Hexnode\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"width\":100,\"height\":100,\"caption\":\"Hexnode\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/Hexnode\\\/\",\"https:\\\/\\\/x.com\\\/thehexnode\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/hexnode\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/c2ed050402be36f7ece23a9b07bc9e64\",\"name\":\"Alanna River\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/1d91e52e837001aa3e782febef8d4339b30257abee06ef86933aebc57aa48248?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/1d91e52e837001aa3e782febef8d4339b30257abee06ef86933aebc57aa48248?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/1d91e52e837001aa3e782febef8d4339b30257abee06ef86933aebc57aa48248?s=96&d=mm&r=g\",\"caption\":\"Alanna River\"},\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/author\\\/alanna-river\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"CrashStealer macOS Malware: Fake Apple CrashReporter Steals Credentials","description":"CrashStealer macOS malware poses as Apple CrashReporter to steal Keychain, browser and password data. Learn XDR and UEM defenses.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.hexnode.com\/threat-watch\/crashstealer-macos-infostealer-keychain-endpoint-risk\/","og_locale":"en_US","og_type":"article","og_title":"CrashStealer macOS Malware: Fake Apple CrashReporter Steals Credentials","og_description":"CrashStealer macOS malware poses as Apple CrashReporter to steal Keychain, browser and password data. Learn XDR and UEM defenses.","og_url":"https:\/\/www.hexnode.com\/threat-watch\/crashstealer-macos-infostealer-keychain-endpoint-risk\/","og_site_name":"Hexnode Threat Watch","article_publisher":"https:\/\/www.facebook.com\/Hexnode\/","article_published_time":"2026-08-19T11:00:17+00:00","article_modified_time":"2026-08-19T14:26:33+00:00","og_image":[{"width":1024,"height":535,"url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/CrashStealer-macOS-malware.webp?format=webp","type":"image\/webp"}],"author":"Alanna River","twitter_card":"summary_large_image","twitter_creator":"@thehexnode","twitter_site":"@thehexnode","twitter_misc":{"Written by":"Alanna River","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":["Article","BlogPosting"],"@id":"https:\/\/www.hexnode.com\/threat-watch\/crashstealer-macos-infostealer-keychain-endpoint-risk\/#article","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/crashstealer-macos-infostealer-keychain-endpoint-risk\/"},"author":{"name":"Alanna River","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/c2ed050402be36f7ece23a9b07bc9e64"},"headline":"CrashStealer macOS Malware: Fake Apple CrashReporter Steals Credentials","datePublished":"2026-08-19T11:00:17+00:00","dateModified":"2026-08-19T14:26:33+00:00","mainEntityOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/crashstealer-macos-infostealer-keychain-endpoint-risk\/"},"wordCount":663,"commentCount":0,"publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/crashstealer-macos-infostealer-keychain-endpoint-risk\/#primaryimage"},"thumbnailUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/CrashStealer-macOS-malware.webp?format=webp","articleSection":["Identity Abuse","macOS"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.hexnode.com\/threat-watch\/crashstealer-macos-infostealer-keychain-endpoint-risk\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.hexnode.com\/threat-watch\/crashstealer-macos-infostealer-keychain-endpoint-risk\/","url":"https:\/\/www.hexnode.com\/threat-watch\/crashstealer-macos-infostealer-keychain-endpoint-risk\/","name":"CrashStealer macOS Malware: Fake Apple CrashReporter Steals Credentials","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/crashstealer-macos-infostealer-keychain-endpoint-risk\/#primaryimage"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/crashstealer-macos-infostealer-keychain-endpoint-risk\/#primaryimage"},"thumbnailUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/CrashStealer-macOS-malware.webp?format=webp","datePublished":"2026-08-19T11:00:17+00:00","dateModified":"2026-08-19T14:26:33+00:00","description":"CrashStealer macOS malware poses as Apple CrashReporter to steal Keychain, browser and password data. Learn XDR and UEM defenses.","breadcrumb":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/crashstealer-macos-infostealer-keychain-endpoint-risk\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.hexnode.com\/threat-watch\/crashstealer-macos-infostealer-keychain-endpoint-risk\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/crashstealer-macos-infostealer-keychain-endpoint-risk\/#primaryimage","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/CrashStealer-macOS-malware.webp?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/CrashStealer-macOS-malware.webp?format=webp","width":1024,"height":535,"caption":"CrashStealer-macOS-malware"},{"@type":"BreadcrumbList","@id":"https:\/\/www.hexnode.com\/threat-watch\/crashstealer-macos-infostealer-keychain-endpoint-risk\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.hexnode.com\/threat-watch\/"},{"@type":"ListItem","position":2,"name":"CrashStealer macOS Malware: Fake Apple CrashReporter Steals Credentials"}]},{"@type":"WebSite","@id":"https:\/\/www.hexnode.com\/threat-watch\/#website","url":"https:\/\/www.hexnode.com\/threat-watch\/","name":"Hexnode Threat Watch","description":"Latest cyber threats, smarter enterprise response.","publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"alternateName":"Threat Watch","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.hexnode.com\/threat-watch\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization","name":"Hexnode","url":"https:\/\/www.hexnode.com\/threat-watch\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","width":100,"height":100,"caption":"Hexnode"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Hexnode\/","https:\/\/x.com\/thehexnode","https:\/\/www.linkedin.com\/company\/hexnode"]},{"@type":"Person","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/c2ed050402be36f7ece23a9b07bc9e64","name":"Alanna River","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/1d91e52e837001aa3e782febef8d4339b30257abee06ef86933aebc57aa48248?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/1d91e52e837001aa3e782febef8d4339b30257abee06ef86933aebc57aa48248?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/1d91e52e837001aa3e782febef8d4339b30257abee06ef86933aebc57aa48248?s=96&d=mm&r=g","caption":"Alanna River"},"url":"https:\/\/www.hexnode.com\/threat-watch\/author\/alanna-river\/"}]}},"_links":{"self":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1113","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/comments?post=1113"}],"version-history":[{"count":3,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1113\/revisions"}],"predecessor-version":[{"id":1119,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1113\/revisions\/1119"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media\/1114"}],"wp:attachment":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media?parent=1113"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/categories?post=1113"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}