Fake “Wavel” Wallet Site Drops PamStealer on Macs

The Hacker News · High sophistication
Last updated September 25, 2026

Researchers report a new PamStealer variant that lures macOS users to a fake cryptocurrency wallet website and tricks them into running a script-based installer. The malware downloads a decryption tool and relies on a live server key exchange, making the real payload harder to analyze and helping the attacker keep control over deployment.

Key findings

  • Victims are lured to a bogus website advertising a fake cryptocurrency wallet service called “Wavel.”
  • The fake site prompts users to click “Download for macOS,” which downloads a DMG (“Wavel.dmg”) containing a compiled AppleScript file.
  • Opening the file launches Script Editor with instructions that lead to execution of a JXA dropper, which then executes a background zsh dropper.
  • The malware downloads a “pkgunpack” decryption utility from attacker infrastructure and performs an X25519 key exchange so the main payload can only be decrypted with server cooperation.
  • Multiple persistence mechanisms are installed, including LaunchAgent, a repair script, and a shell hook appended to ~/.zshrc.
  • Additional persistence is created by setting a global Git hooks path so normal git commit/checkout activity triggers the repair script.
  • The final stealer attempts to capture the user’s system password via a fake crash dialog and also steals keychain items and browser credentials.

Who’s being targeted

  • Commonly targeted roles: All Employees, Executives, Finance, Developers, IT Support / Helpdesk.
  • Affected industries: Technology (software development / engineering teams), Financial services / cryptocurrency users (consumer-targeted).
  • Attack channels: website.
  • Impersonated: Wavel (fake cryptocurrency wallet service), Wavel installer / Apple Script Editor workflow.

Awareness takeaways

  • Treat “download for macOS” prompts on unfamiliar websites (especially crypto-related) as high-risk and verify the vendor through official channels before installing anything.
  • Do not follow installation steps that involve running scripts in Script Editor/Terminal; report them to IT/Security instead.
  • Be alert for persistence tricks that hide inside normal work tools (like Git); unexpected global config changes are a warning sign.
  • If a prompt claims your password is needed due to a crash or system issue, stop and verify, attackers may use fake dialogs to capture credentials.

Red flags to watch for

  • Unknown/new crypto wallet brand with a too-convenient macOS download
  • Software download comes from a lookalike domain rather than a well-known app store or vendor site
  • Download leads to a DMG installer rather than a trusted distribution channel
  • Installer requires running a script in Script Editor (unusual for legitimate apps)
  • Instructions encourage manual script execution rather than a signed, standard installer
  • Background execution behavior after running a script
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You land on wavel.app, a slick crypto site, big button saying “Download for macOS.” Looks legit, right? You click. It drops “Wavel.dmg.” Open it, and instead of a normal installer, Apple’s Script Editor pops up, telling you to run a script. That script quietly pulls down PamStealer and buries itself in zsh and your Git hooks. Behind the scenes, it downloads a hidden decryptor, does a fancy key exchange with a remote server, sets LaunchAgents, edits your ~/.zshrc, even hijacks global Git hooks so normal commits keep reinstalling it. Then a fake crash dialog pops up asking for your Mac password. Here’s the move: if a random crypto site wants you to install a DMG and run scripts in Script Editor or Terminal, stop right there and send the link and file to IT or Security instead.

Similar attacks

Fake GitHub Lure Tricks macOS Users Into Stealer

Fake GitHub Lure Tricks macOS Users Into Stealer

Researchers described AmnesiaStealer, a macOS info-stealer spread through a counterfeit “Download for macOS” page that tricks users into pasting a command into Terminal. The malware steals passwords and browser session data, and can even give an attacker live, hidden control of the victim’s browser…

August 17, 2026
Fake GitHub “ClickFix” Spreads macOS AmnesiaStealer

Fake GitHub “ClickFix” Spreads macOS AmnesiaStealer

Researchers say a real macOS malware campaign is using “ClickFix” social engineering to trick users into installing an infostealer called AmnesiaStealer. Victims are lured to a counterfeit GitHub download page that encourages them to copy/paste a Terminal command, which then downloads and runs the…

August 14, 2026
Fake CAPTCHA ‘ClickFix’ Spreads Lunex Stealer

Fake CAPTCHA ‘ClickFix’ Spreads Lunex Stealer

Attackers compromised legitimate Ukrainian websites and showed visitors a fake CAPTCHA/Cloudflare-style “verification” prompt to trick them into installing malware. The infection chain drops Lunex (aka Psychedelic Stealer), which disables security monitoring using a vulnerable AMD driver and then…

September 26, 2026
Malicious Calendar Invites Surge With Malware Links

Malicious Calendar Invites Surge With Malware Links

Attackers are sending fake calendar meeting invites that can be automatically added to a victim’s calendar, even if the email is blocked. A documented example used a Google Calendar invite with a financial “invoice credit” lure to drive victims to a hosted webpage and download a malicious…

September 18, 2026
AI Voice “Apple Support” Phishing + Fake IT Helpdesk

AI Voice “Apple Support” Phishing + Fake IT Helpdesk

This news roundup describes real social-engineering operations where attackers impersonate trusted support teams to trick people into giving up secrets. One campaign uses email/SMS/WhatsApp plus AI voice calls pretending to be Apple Support to steal iPhone passcodes, while another uses phishing…

August 27, 2026
Typosquat RubyGems Stealer Hits Dev Machines

Typosquat RubyGems Stealer Hits Dev Machines

Researchers found 16 look‑alike (typosquatted) RubyGems packages that trick developers into installing a Windows information stealer. The malicious gems run code automatically during installation, pull down additional malware, and then steal browser logins and crypto wallet data before uploading it…

August 18, 2026