New macOS Malware Campaign Targets Crypto Wallet Users

A new macOS malware campaign is targeting cryptocurrency users by harvesting browser credentials and wallet data, marking a shift in attacker tactics toward credential theft.
Summary:
- The malware harvests sensitive data from macOS devices, including browser credentials and wallet-related files.
- Researchers linked the campaign to phishing pages disguised as community onboarding websites.
- Similar macOS information stealers have emerged in recent days, pointing to a broader threat trend.
- Security experts recommend treating an infected device as fully compromised.
According to SlowMist, the latest campaign relies on social engineering rather than software vulnerabilities, reflecting a broader shift in cybercrime toward compromising users instead of blockchain networks.
The attackers reportedly create fake community application websites, including pages impersonating projects such as BuilDAO and Builder, using Google Sites to increase credibility. Victims are presented with fabricated system or OAuth-related errors and persuaded to download what appears to be a required application or security update.
Once installed, the malware quietly collects sensitive information stored across the operating system. Researchers said the malware extracts credentials from the macOS Keychain, browser databases used by applications such as Chrome, Brave and Arc, Apple Notes, and Telegram Desktop session files, giving attackers access to both financial and personal accounts.
The findings illustrate a growing preference among threat actors for stealing authentication data that can unlock cryptocurrency wallets, cloud services and communication platforms rather than attempting direct attacks on blockchain infrastructure.
Crypto Wallets Become a Primary Target
SlowMist said the malware is specifically designed to identify cryptocurrency-related files stored on compromised devices.
Among its capabilities is the ability to facilitate wallet replacement attacks, in which legitimate wallet software such as Ledger or Trezor is replaced with modified versions capable of capturing recovery phrases or other sensitive credentials. Because victims often believe they are interacting with authentic software, the technique can bypass many of the protections built into hardware wallets.
READ MORE: Hedera DeFi Protocol Bonzo Lend Suffers $9M Oracle Attack
The campaign also demonstrates how phishing operations are becoming increasingly specialized. Instead of indiscriminately stealing passwords, attackers are prioritizing information that provides direct access to digital assets, reflecting the higher financial value associated with cryptocurrency users.
The latest disclosure comes as researchers continue to report more sophisticated malware targeting Apple’s desktop operating system, challenging the long-held perception that macOS users face significantly lower cybersecurity risks than Windows users.
Recent Campaigns Point to a Broader Trend
The SlowMist investigation follows the discovery of several macOS information-stealing campaigns reported this week, including ClickLock Stealer, which repeatedly forces password prompts until users comply, and CrashStealer, which impersonates Apple’s Crash Reporter to gain trust before harvesting credentials.
Taken together, the campaigns suggest attackers are increasingly investing in malware designed specifically for Apple’s ecosystem while refining social engineering techniques that require little technical exploitation.
For users who suspect their device has been compromised, security researchers recommend assuming that all locally stored credentials are exposed. Rather than simply deleting suspicious files, affected users should move cryptocurrency assets using a separate trusted device, perform a clean installation of macOS, rotate passwords, revoke active sessions, replace API and SSH keys where applicable, and download future software only from verified developer sources.
As digital assets become more widely adopted, security experts say protecting wallets increasingly depends on safeguarding the devices that store access credentials, making endpoint security as important as blockchain security itself.
The information presented in this article is intended for informational purposes only and should not be interpreted as financial, investment, or trading advice. Coinspress.com does not promote or advocate for any particular investment strategy, asset, or cryptocurrency project. Cryptocurrency markets are highly volatile and unpredictable – always perform your own research and seek guidance from a qualified financial professional before making any investment decisions.











