{"id":398822,"date":"2026-08-02T04:06:50","date_gmt":"2026-08-02T04:06:50","guid":{"rendered":"https:\/\/malwaretips.com\/blogs\/?p=398822"},"modified":"2026-08-02T04:06:50","modified_gmt":"2026-08-02T04:06:50","slug":"crashstealer-malware-on-mac-how-the-fake-crash-reporter-steals-passwords","status":"publish","type":"post","link":"https:\/\/malwaretips.com\/blogs\/crashstealer-malware-on-mac-how-the-fake-crash-reporter-steals-passwords\/","title":{"rendered":"CrashStealer Malware on Mac: How the Fake Crash Reporter Steals Passwords"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">CrashStealer is a serious macOS information stealer disguised as Apple&#8217;s crash-reporting software. It uses a convincing password prompt to unlock the victim&#8217;s Keychain and quietly searches the Mac for credentials, browser sessions, wallets and files.<\/p><div id=\"mwtad1858128732\" class=\"gas_fallback-ad_309684--placement_360520\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3957935887\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">If you installed <strong>Werkbit Setup<\/strong>, saw an unexpected Crash Reporter password request or found <strong>CrashReporter.dmg<\/strong>, disconnect the Mac immediately. Change passwords only from another trusted device because the compromised Mac may still be collecting them.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" width=\"1536\" height=\"1024\" src=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/08\/crashstealer-mac-malware.png\" alt=\"CrashStealer malware stealing passwords and wallet data from a Mac\" class=\"wp-image-398801\" title=\"\" srcset=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/08\/crashstealer-mac-malware.png 1536w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/08\/crashstealer-mac-malware-300x200.png 300w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/08\/crashstealer-mac-malware-1024x683.png 1024w\" sizes=\"(max-width: 1536px) 100vw, 1536px\" \/><figcaption class=\"wp-element-caption\">CrashStealer impersonates a macOS crash reporter while collecting Keychain credentials, browser data, cryptocurrency wallets and files.<\/figcaption><\/figure>\n\n\n\n<div id=\"mwtad800590355\" class=\"gas_fallback-ad_309746-ad_309691-placement_360521\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"4456629336\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2 class=\"wp-block-heading\">CrashStealer Malware Overview<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">CrashStealer is a C++ information stealer built for macOS. Its observed delivery chain began with a disk image called Werkbit Setup, distributed through a fake software website. The installer was signed and notarized with a valid Apple developer certificate, allowing it to pass Gatekeeper checks that users often treat as proof that an application is safe. A valid signature confirms who signed a file; it does not guarantee that the software is harmless.<\/p><div id=\"mwtad1142087033\" class=\"gas_fallback-ad_381396-ad_309691-placement_360566\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"1471373341\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">After the first installer runs, it contacts a remote server, retrieves a shell script and downloads CrashReporter.dmg. The payload is hidden, re-signed and launched under an Apple-like identity. Its bundle identifier com.apple.crashreporter and familiar crash-reporting imagery help it blend in with normal macOS activity.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The stealer then displays a fake macOS password dialog. When the victim enters the account password, CrashStealer validates it locally and uses it to unlock Keychain data. This can expose saved Safari logins, Wi-Fi passwords, certificates and cryptographic keys. The malware also searches Chromium and Firefox-based browsers, around 80 cryptocurrency wallet extensions, 14 password managers and files stored in Desktop, Documents and Downloads.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Data CrashStealer is designed to collect<\/h3>\n\n\n\n<ul class=\"wp-block-list\"><li>macOS account credentials entered into the fake password prompt.<\/li><li>Keychain entries, Safari passwords, Wi-Fi credentials and cryptographic material.<\/li><li>Saved browser passwords, cookies, browsing data and active session information.<\/li><li>Cryptocurrency wallet extensions and related wallet data.<\/li><li>Password-manager application data from widely used products.<\/li><li>Documents and other files found in Desktop, Documents and Downloads.<\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">CrashStealer maintains persistence through a LaunchAgent named <strong>com.apple.crashreporter.helper<\/strong>, allowing it to return when the user signs in or the Mac restarts. It encrypts important strings, checks for debuggers and packages stolen information into hidden archives before exfiltration. The result can be email takeover, financial fraud, cryptocurrency theft, identity theft and compromise of additional accounts long after the original installer disappears.<\/p><div id=\"mwtad4287499746\" class=\"gas_fallback-ad_309686-ad_309691-placement_360569\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"6935453015\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n\n\n\n<div id=\"mwtad2362591101\" class=\"gas_fallback-ad_309747-ad_309691-placement_360587\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"9589536513\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2 class=\"wp-block-heading\">How the CrashStealer Mac Infection Works<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">Step 1: The victim receives the Werkbit Setup installer<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The observed campaign used a fake software site and a meeting PIN to restrict access to the download. That extra friction can make a targeted file appear exclusive or business-related. The disk image carried a legitimate-looking signature and notarization, reducing the warnings a user would normally expect.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Step 2: The signed installer passes the first trust check<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">macOS Gatekeeper recognizes the developer certificate and permits the installer to run. This is the point the campaign exploits: many people assume that an allowed application has been reviewed for every malicious behavior, when a stolen or abused certificate can sign harmful code.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Step 3: A script downloads CrashReporter.dmg<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Werkbit Setup silently reaches a remote server and retrieves a shell script. That script downloads the actual stealer payload. Splitting the attack into two stages lets the first file look simpler and gives the operator control over what the victim receives next.<\/p><div id=\"mwtad3523159618\" class=\"gas_fallback-ad_381401-ad_309691-placement_360573\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"5315249587\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n\n\n\n<h3 class=\"wp-block-heading\">Step 4: The payload adopts an Apple-like identity<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The malware is copied into a hidden directory and launched as a fake crash-reporting component. Its name, icon and bundle identifier are selected to resemble a legitimate macOS process. Re-signing the binary also changes its file hash, complicating simple hash-based blocking.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Step 5: A fake password prompt unlocks sensitive data<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">CrashStealer asks for the Mac account password using a system-style dialog. Once supplied, the password can unlock Keychain entries and allow the malware to gather credentials that would otherwise remain protected.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Step 6: Credentials and files are archived and stolen<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The stealer searches browsers, password managers, wallet extensions and personal folders. Collected data is compressed into concealed archives and uploaded to attacker-controlled infrastructure. A LaunchAgent helps the malware repeat this collection after a restart.<\/p><div id=\"mwtad3911694601\" class=\"gas_fallback-ad_381404-ad_309691-placement_381406\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"8735619847\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n\n\n\n<div id=\"mwtad4108324330\" class=\"gas_fallback-ad_309748-ad_309691-placement_360588\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3906789406\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2 class=\"wp-block-heading\">Warning Signs of a Possible CrashStealer Infection<\/h2>\n\n\n\n<ul class=\"wp-block-list\"><li>Werkbit Setup or CrashReporter.dmg appears in Downloads, mounted volumes or recent items.<\/li><li>A Crash Reporter window asks for the macOS account password without a clear reason.<\/li><li>An unfamiliar application uses the com.apple.crashreporter identity or Apple-like iconography.<\/li><li>A LaunchAgent named com.apple.crashreporter.helper appears in the user Library.<\/li><li>Browsers, password managers or cryptocurrency accounts show unfamiliar sessions or changes.<\/li><li>The Mac repeatedly contacts an unknown server while apparently idle.<\/li><li>Hidden ZIP archives or suspicious staging folders appear near user data.<\/li><li>Passwords stop working or account recovery details change unexpectedly.<\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">CrashStealer is designed to remain quiet, so the absence of pop-ups does not clear the Mac. The strongest indicators are the installer names, unexpected password request, LaunchAgent and subsequent account activity.<\/p>\n\n\n\n<div id=\"mwtad3647040713\" class=\"gas_fallback-ad_318930-ad_309691-placement_360589\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3818335085\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2 class=\"wp-block-heading\">What to Do If CrashStealer May Be on Your Mac<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">Disconnect the Mac from the internet<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Turn off Wi-Fi and unplug any network adapter. Do not sign in to email, banking or cryptocurrency services from the suspected Mac. Isolation interrupts exfiltration and prevents the attacker from receiving newly collected data.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Secure important accounts from another device<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Use a clean phone or computer. Change the primary email password first, then Apple Account, banking, cloud storage, work accounts, password managers and cryptocurrency services. End active sessions, revoke connected apps and enable multi-factor authentication.<\/p><div id=\"mwtad1119789226\" class=\"gas_fallback-ad_360582-ad_309691-placement_360581\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"9971336976\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n\n\n\n<h3 class=\"wp-block-heading\">Protect cryptocurrency immediately<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">If wallet data or recovery phrases were stored on the Mac, move assets to a new wallet created on a clean device. Merely changing an exchange password cannot protect a wallet whose seed phrase or private key was stolen.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Check for persistence and related components<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Review Login Items, LaunchAgents, recently installed applications, mounted disk images and downloads. The name com.apple.crashreporter.helper is a strong lead, but do not assume it is the only component. An experienced responder should preserve copies and logs before removal on a business Mac.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Run a complete macOS security scan<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Use a reputable Mac security product with current definitions. Scan the entire system, including user Library folders. If the account password was entered into the fake prompt or sensitive business data was accessible, a clean macOS reinstall is safer than relying on removal of one visible file.<\/p><div id=\"mwtad3901050095\" class=\"gas_fallback-ad_360567-ad_309691-placement_360771\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"6224621518\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n\n\n\n<h3 class=\"wp-block-heading\">Review every account for follow-on abuse<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Inspect sign-in history, email forwarding rules, recovery methods, trusted devices and financial transactions. Remove unfamiliar browser extensions and profiles. Contact banks, employers or wallet providers quickly when money or company data may be at risk.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Also review files that were available in Desktop, Documents and Downloads. If they contained identity documents, tax records, client data or recovery codes, assume copies may have left the Mac. Notify the relevant organization and monitor for targeted fraud rather than waiting for the stolen material to appear publicly.<\/p>\n\n\n\n<div id=\"mwtad345597111\" class=\"gas_fallback-ad_381388-ad_309691-placement_381390\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3191649120\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2 class=\"wp-block-heading\">How to Avoid Similar macOS Stealers<\/h2>\n\n\n\n<ul class=\"wp-block-list\"><li>Download applications from the Mac App Store or the developer&#8217;s verified official site.<\/li><li>Treat a valid signature or notarization as one security signal, not a complete safety verdict.<\/li><li>Do not enter the Mac password into a prompt triggered by an application you did not intentionally install.<\/li><li>Keep macOS, browsers and security software updated.<\/li><li>Avoid pirated applications, cracks, key generators and private download links from strangers.<\/li><li>Store cryptocurrency recovery phrases offline rather than in documents or browser notes.<\/li><li>Use separate passwords and multi-factor authentication for important accounts.<\/li><li>Maintain a current backup that is not permanently writable from the Mac.<\/li><\/ul>\n\n\n\n<div id=\"mwtad2848848408\" class=\"gas_fallback-ad_381392-ad_309691-placement_381395\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"2944237110\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2 class=\"wp-block-heading\">The Bottom Line<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">CrashStealer is a sophisticated macOS credential thief that hides behind a fake crash reporter and abuses a convincing password prompt. Its targets include Keychain data, browser sessions, password managers, cryptocurrency wallets and personal files.<\/p><div id=\"mwtad1337051941\" class=\"gas_fallback-ad_360571-ad_309691-placement_360772\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"5867729999\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">Do not dismiss the incident after deleting Werkbit Setup or CrashReporter.dmg. Isolate the Mac, scan or rebuild it, rotate credentials from a clean device and review financial and cryptocurrency activity. The stolen data can remain valuable to attackers even after the malware itself is removed.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>CrashStealer is a macOS information stealer disguised as an Apple crash-reporting process. It targets Keychain passwords, browsers, wallets, password managers and personal files.<\/p>\n","protected":false},"author":50,"featured_media":398801,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"ai_generated_summary":"","footnotes":""},"categories":[2836,2728],"tags":[],"class_list":["post-398822","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-malware-removal-and-popup-scam-alerts","category-trojans","masonry-post","generate-columns","tablet-grid-50","mobile-grid-100","grid-parent","grid-50","resize-featured-image"],"_links":{"self":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/398822","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/users\/50"}],"replies":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/comments?post=398822"}],"version-history":[{"count":2,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/398822\/revisions"}],"predecessor-version":[{"id":398849,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/398822\/revisions\/398849"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/media\/398801"}],"wp:attachment":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/media?parent=398822"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/categories?post=398822"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/tags?post=398822"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}