Cybersecurity experts have recently identified a new version of the PamStealer malware targeting macOS users. This updated variant introduces a sophisticated method for payload decryption by utilizing a server-side decryption chain. Unlike its predecessors, the decryption process now requires a server-side key exchange, making static analysis nearly impossible without an active command-and-control session. The malware continues to use JavaScript for Automation (JXA) as its dropper mechanism but has altered its delivery method and decoy tactics. Researchers from Jamf Threat Labs reported that the malware now employs a phony website advertising a non-existent cryptocurrency wallet service called Wavel to lure victims. When users interact with the fake site, they download a disk image file that launches Apple's Script Editor to execute a JXA dropper.

Previously, the JXA source managed the decryption and execution processes directly, but in this variant, the JXA layer merely serves as a carrier. Upon execution, it decodes a base64 string and passes it to a zsh script that continues the infection process in the background. This design shift ensures that the payload remains protected, as the Data Encryption Key cannot be recovered without the server's private key. Additionally, a new ephemeral keypair is generated with each execution to prevent the replay of captured keys.

The malware's persistence mechanism is also enhanced. It copies a repair script into specific git hook directories, ensuring that any git action on a compromised system activates the script. The final payload, a stealer component now written in Swift, targets an expanded list of browsers, including Arc and Zen. This change signifies a strategic investment in delivery infrastructure. The integration of a live key exchange underscores the importance of server cooperation, making it challenging to recover the payload statically and shifting control to the server operator.