User '_mbsetupuser' with shell '/bin/bash' in file '/etc/passwd' (MacOS Big Sur). Me hacked?
Hello! The day before yesterday I was presented with a MacBook Pro 12.1 laptop. I immediately decided to update the system there to the new latest MacOS Big Sur (clean installation from a USB drive, the laptop disk was completely erased before installation). The system installed fine, but after a few hours I found a strange thing in it... The following line was found in the /etc/passwd file:
_mbsetupuser:*:248:248:Setup User:/var/setup:/bin/bash
I apologize, but I have never used MacOS before, I only used ArchLinux before, and there, if some strange user is registered in the /etc/passwd file who works with the /bin/bash shell, then this means that most likely the system was hacked... Or is it ok for macOS Big Sur 11.5.2? Who is this user _mbsetupuser and why does he need /bin/bash ??? Is it possible to somehow track the activity of this user from the moment of his first login to the system?
A screenshot with the terminal output is attached below. Thank you all in advance for any information on this issue!
UPD #1 - groups this user:
uid=248(_mbsetupuser) gid=248(_mbsetupuser) groups=248(_mbsetupuser),12(everyone),61(localaccounts),250(_analyticsusers),701(com.apple.sharepoint.group.1),100(_lpoperator)
UPD #2 - I found another interesting user almost at the very beginning of /etc/passwd. Why is it needed and what kind of shell is it? Here is the line:
_uucp:*:4:4:Unix to Unix Copy Protocol:/var/spool/uucp:/usr/sbin/uucico