Newly discovered PamStealer isn't your typical macOS malware

2026-07-05T08:51:47Z14053cf73d7ddf8487fcb62cd2173842fdb57e64e7be4dbc73712d6999572874
2fabackdoorcopilotcredential‑theftcryptocurrencycrypto‑clipperdata‑breachinfostealerlinux‑kernelmacosmalwareoperation‑endgamepackage‑malwarepamstealerpeopleSoftrussiasearchleaksignalstate‑sponsoredsupply‑chaintorusb‑spreadinguse‑after‑freewhatsapp','ai‑security','llm‑guardrails','ai‑browsers','quantum‑zero‑day

What happened

Ars Technica's security feed documents a wave of high-impact incidents and shifting threat trends: a new macOS infostealer dubbed PamStealer using stealthy tradecraft; a lightweight USB-spreading/Tor-communicating crypto-stealing backdoor (Crypto Clipper); widespread credential exfiltration from a massive breach affecting many large vendors; multiple zero-days (notably a critical PeopleSoft 0-day and a Linux kernel use‑after‑free); a Copilot/SearchLeak flaw that can expose 2FA codes; package- and supply-chain delivered credential stealers; and a global law‑enforcement disruption ("OperationEnd

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
arstechnica_security
Record identifier
14053cf73d7ddf8487fcb62cd2173842fdb57e64e7be4dbc73712d6999572874
Enrichment time
2026-07-05T08:51:47Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.