🔧 AI Nachrichten The Next Terrorist Attack Is Predictable(10.09.2026 um 23:41 Uhr)
🔧 AI Nachrichten Could A.I. Really Kill All Humans?(10.09.2026 um 23:53 Uhr)
🔧 AI Nachrichten Amazon Prime Video Uses A.I. for Lip-Synced Translations(11.09.2026 um 01:56 Uhr)
🔧 AI Nachrichten McClatchy Makes Deep Job Cuts to Newspapers Around the Country(11.09.2026 um 04:25 Uhr)
🔧 AI Nachrichten Law schools tell students to put AI away(07.09.2026 um 16:37 Uhr)
🔧 AI Nachrichten Can Huawei build China’s answer to ASML?(08.09.2026 um 04:57 Uhr)
🔧 AI Nachrichten AI is ushering in an era of mass toe-treading at work(08.09.2026 um 06:00 Uhr)
🔧 AI Nachrichten The Next Terrorist Attack Is Predictable(10.09.2026 um 23:41 Uhr)
🔧 AI Nachrichten Could A.I. Really Kill All Humans?(10.09.2026 um 23:53 Uhr)
🔧 AI Nachrichten Amazon Prime Video Uses A.I. for Lip-Synced Translations(11.09.2026 um 01:56 Uhr)
🔧 AI Nachrichten McClatchy Makes Deep Job Cuts to Newspapers Around the Country(11.09.2026 um 04:25 Uhr)
🔧 AI Nachrichten Law schools tell students to put AI away(07.09.2026 um 16:37 Uhr)
🔧 AI Nachrichten Can Huawei build China’s answer to ASML?(08.09.2026 um 04:57 Uhr)
🔧 AI Nachrichten AI is ushering in an era of mass toe-treading at work(08.09.2026 um 06:00 Uhr)

⚠️ Malware / Trojaner / Viren 🕛 vor 1 Monat 5 Min Lesezeit SECURITY-FEED
0

5 months of undetected JXA backdoor on macOS. signature scanners found nothing, manual persistence check found it in 10 seconds

↗ Quelle (reddit.com)
🗣️ Stimme:

Background: developer, cybersecurity basics but not a security professional. Working on a M Chip Mac. Posting as a writeup and to sanity-check my analysis and response.

Discovery

Auditing login items in ~/Library/LaunchAgents/. Normally vendor-named (com.google.keystone.agent), but one entry was a bare 32-character hex string pointing to a JS file in an identically-named directory.

xml

CODE
ProgramArguments: /usr/bin/osascript -l JavaScript ~/Library/Application Support/<hex>/<hex>.js RunAtLoad: true KeepAlive: true ThrottleInterval: 60 StandardOutPath: /dev/null StandardErrorPath: /dev/null 

RunAtLoad/KeepAlive = starts at login, respawns on crash. Both output paths to /dev/null = zero logging by design.

The payload

Obfuscated (string-array rotation, a0_0x... identifiers, anti-beautify self-check, console hijacking). Working through it:

Fingerprinting: MD5 of the hardware UUID sent as User-Agent — stable per-host ID, survives reinstalls.

Polling: curl to a random-looking C2 domain every 60s via /api/poll.

Proof-of-work gating: server sends a challenge + difficulty; client brute-forces a nonce until SHA256(nonce-challenge) hits N leading zeros before getting a session token. Not security — anti-analysis. Burns sandbox CPU and filters out short-lived research environments.

Execution: response type field branches to osascript -l JavaScript, osascript (AppleScript), or curl | bash — all backgrounded, output discarded, payloads piped via stdin so nothing hits disk.

Ack loop: separate PUT confirming task completion, same PoW handling.

Key point

No credential-harvesting code, no keylogger, no exfil routine — it's a generic execution channel. What it did over 5 months is entirely dependent on what was pushed to it, and unknowable since nothing was logged.

Running as user (no root) but with osascript, reachable surface on a dev box: git tokens in .git/config, passphrase-less SSH keys, .env files, certs on disk, unprotected keychain items (plus AppleScript can render fake password prompts for protected ones), browser cookies/sessions, and screen capture. Secure Enclave–bound passkeys/Touch ID items held — not reachable by a software process, any attempt triggers an unspoofable OS prompt.

Install date (Spotlight kMDItemDateAdded): Feb 13. Found late July — ~5.5 months.

Why detection failed

Commercial AV installed the whole time; ran ClamAV afterward too. Zero detections, both, even knowing the exact path. Signature engines hash/pattern-match against known-bad corpora — useless against a bespoke, obfuscated, one-off sample. Nothing here is structurally illegal either: osascript is first-party Apple, a .js file + LaunchAgent plist are ordinary primitives. Only the naming convention and combination were anomalous — semantic signals a heuristic/behavioral engine could catch, not a signature one.

The actual detection method: ls -la ~/Library/LaunchAgents/.

Forensics: mostly a dead end

LSQuarantineEvent DB empty for that window (suggests the file was written by a running process, not browser-downloaded), Downloads/browser history clean, .zsh_history rotated out (SAVEHIST=1000), npm logs only back to July, unified log retention nowhere near 5 months, Time Machine's oldest backup postdates the incident.

Ruled out: no ClickFix-style paste-into-terminal.

What lines up temporally: a short GitHub Copilot session that evening, working on a payments API integration — chat history long gone. Circumstantial, not proof. But there are documented issues with AI coding agents: indirect prompt injection leading to unapproved shell execution, hidden-unicode instructions in config/rules files, hallucinated package names pre-registered by attackers. A compromised npm postinstall hook is equally plausible. Genuinely don't know.

Response:

Containment: unloaded LaunchAgent, killed process, removed plist + payload dir.

Verification (4 independent passes):

  • KnockKnock (structural persistence enumeration, checks code signing) — everything else attributable/notarized
  • Reboot + launchctl list | grep -v
    Vollständiger Original-Bericht
    Ausführliche Details, Code-Beispiele & Hersteller-Stellungnahme auf reddit.com.
    ↗ Original-Artikel auf reddit.com lesen
Wie bewertest du diesen Beitrag?
1 Klick Feedback
Teilen mit Netzwerk & Team:
Community Threat-Level Barometer
Live Votum

Wie stufst du das Risiko dieser Schwachstelle / Bedrohung für dein Unternehmen ein?

Noch keine Stimmen — schätze das Risiko als Erster ein.

Community-Analysen & Experten-Meinungen 0

Verfasse deine eigene Analyse, teile Workarounds oder diskutiere diesen Vorfall im Blog.
Noch keine Community-Analyse verfasst. Markiere einen Textabschnitt oder klicke oben auf Eigene Analyse verfassen“!
Community Pulse: Relevanz-Einschätzung
1 Klick Experten-Votum
🔴 Akute Relevanz 0%
🟡 In Evaluierung 0%
🟢 Keine Auswirkung 0%
Spannende Innovation 0%
Verwandte Story-Cluster & Quellen (Vektor-KI)
Port 8095 Engine
2 Quellen
Could A.I. Really Kill All Humans?
1 Quelle
The Next Terrorist Attack Is Predictable
1 Quelle
Anthropic Says It Blocked Possible Efforts to Build Biological Weapons