CrashStealer is a new macOS information-stealing malware that bypassed macOS gatekeeper by using Apple-validated credentials and developer name. It begins with the user downloading a malicious installer, "Werkbit.app," after entering a specific meeting PIN on a malicious website. It works with a social engineering scam and bypasses automatic macOS protections by walking the user through the infection process. It harvests sensitive data like passwords and crypto wallets. Finally, it encrypts the stolen information and exfiltrates it to an attacker-controlled server while using advanced techniques to delay and resist analysis from the target.