How do I handle suspected malware in macOS and protect my MacBook Pro?
Its just couple of days since I started setting up my new MacBook Pro, and see what I found:
A file ~/Library/LaunchAgents/com.ntpebadwvugmokrc.plist was created automatically and is running now.
also found ~/.passphrase, a hidden file associated with this campaign. The documented malware uses it to hold the Mac login password after showing a fake system prompt. I did not open the file, so I cannot confirm what it contains or prove what was transmitted. Treat your Mac password—and accounts accessible from this Mac—as potentially compromised.
It is set to stay running, hides an AppleScript inside base64, and launches a command that contacts an external site and pipes the response to osascript. That is strong evidence of unauthorized remote-code execution behavior—not a normal Mac item. I cannot determine from this inspection what the remote code did or whether data was taken.
I have collected the evidence and resetting my Macbook as temporary solution.
Does any one else has similar experience?
In plain language, it does this:
- Starts at login and tries to stay running. The file has RunAtLoad and KeepAlive enabled. It was still running when I checked at 2:04 PM today.
- Hides its instructions. It takes a long encoded string, decodes it, and runs it as an AppleScript.
- Looks up where to connect. The AppleScript asks several Polygon blockchain servers for a value that it decodes into a server address. This is a way to change its destination without editing the file;
- Downloads and runs more instructions. It sends an identifier to that server and pipes the server’s response directly into osascript. In effect, whoever controls that response can supply code for the Mac to run.
- Important distinction: this file shows the loader—how it fetches and runs further code. It does not contain the full code returned by the server, so the file alone cannot tell us exactly what was accessed or whether anything was stolen. The separate .passphrase file we found remains a serious concern, but I dont understand its contents.
[Re-Titled by Moderator]
Original Title: suspected malware in macOS
MacBook Pro 14″, macOS 26.5