Newly discovered PamStealer isn't your typical macOS malware
2026-07-05T08:51:47Z•14053cf73d7ddf8487fcb62cd2173842fdb57e64e7be4dbc73712d6999572874
2fabackdoorcopilotcredential‑theftcryptocurrencycrypto‑clipperdata‑breachinfostealerlinux‑kernelmacosmalwareoperation‑endgamepackage‑malwarepamstealerpeopleSoftrussiasearchleaksignalstate‑sponsoredsupply‑chaintorusb‑spreadinguse‑after‑freewhatsapp','ai‑security','llm‑guardrails','ai‑browsers','quantum‑zero‑day
What happened
Ars Technica's security feed documents a wave of high-impact incidents and shifting threat trends: a new macOS infostealer dubbed PamStealer using stealthy tradecraft; a lightweight USB-spreading/Tor-communicating crypto-stealing backdoor (Crypto Clipper); widespread credential exfiltration from a massive breach affecting many large vendors; multiple zero-days (notably a critical PeopleSoft 0-day and a Linux kernel use‑after‑free); a Copilot/SearchLeak flaw that can expose 2FA codes; package- and supply-chain delivered credential stealers; and a global law‑enforcement disruption ("OperationEnd
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- arstechnica_security
- Record identifier
- 14053cf73d7ddf8487fcb62cd2173842fdb57e64e7be4dbc73712d6999572874
- Enrichment time
- 2026-07-05T08:51:47Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.