Hackers can steal macOS keychain passwords using unsigned applications, it works on the latest version of macOS, High Sierra 10.13, and previous releases. The attack does not require the knowledge of the master password, it only needs the targeted user to download and launch a malicious application, ignoring warnings displayed when an app from an unidentified developer is being executed. By default the keychain is unlocked when the user logs in, but you can change the password (so it is not automatically unlocked during login, or lock it while not using it.”]
Source: https://securityaffairs.co/wordpress/63439/hacking/os-keychain-data-theft.html

