WARNING--CrashStealer Poses as Apple's CrashReporter; SHub Fakes a Security Update. Both Want Your Keychain
Two things to watch for on your Mac this month. The first, CrashStealer, spreads through a fake installer for the Werkbit videoconferencing app; the site asks for a PIN, hands you a "Werkbit Setup" that is signed with a valid Apple developer certificate, so Gatekeeper lets it through, and installs a process that calls itself CrashReporter with Apple's app identifier and a look-alike icon. Kaspersky first saw it in May and had it in the wild by early July. It goes after the Keychain, fourteen password managers including 1Password, LastPass and Bitwarden, browser data, some eighty cryptocurrency wallet extensions, and your Documents and Downloads folders.
The second is a new variant of the SHub infostealer that uses AppleScript to put up a fake "security update" dialog and installs a backdoor when you click through, per BleepingComputer. Both belong to the family of ClickFix attacks that Microsoft documented in May, where a web page walks you through pasting a command into Terminal, and to the Go-based stealer Huntress found in June.
What to do. Apple's own update dialogs come from System Settings, never from a web page or a script; if a "security update" appears while you are in a browser, it is not Apple's. Never paste a Terminal command a web site gives you. And install macOS Tahoe 26.6.2, released August 17, which back-ports fixes first shipped in the Golden Gate beta; the CVE list is on Apple's security releases page and in the APPLE-SA-08-17-2026-3 advisory.
A signed installer is no longer proof of anything; it is proof the attacker paid $99. Treat the Keychain like cash. [Macs Only!]
Sources
- Kaspersky, “CrashStealer, a new infostealer for macOS: how it works and how to stay safe” accessed Sep 9, 2026
Delivery via fake Werkbit installer, CrashReporter disguise, data targeted, timeline.
- BleepingComputer, “SHub macOS infostealer variant spoofs Apple security updates” accessed Sep 9, 2026
AppleScript fake update dialog and backdoor.
- Microsoft Security Blog, “ClickFix campaign uses fake macOS utilities lures to deliver infostealers” accessed Sep 9, 2026
ClickFix technique on macOS.
- Infosecurity Magazine, “Go-Based macOS Malware Steals Crypto and Secrets” accessed Sep 9, 2026
Huntress discovery of the Go-based stealer.
- Apple Support, “About the security content of macOS Tahoe 26.6.2” accessed Sep 9, 2026
Release date and fixed CVEs.
- Apple Support, “Apple security releases” accessed Sep 9, 2026
Index of current security updates.
- Full Disclosure mailing list, “APPLE-SA-08-17-2026-3 macOS Tahoe 26.6.2” accessed Sep 9, 2026
The advisory as distributed.
Saw something? Send a tip
The archive ran on reader tips. What did you see, where, and do you want the credit?