Best Cyber Solutions Request service

October 7, 2026 · 2 min read

What a compromised Mac actually looks like

Not a skull on the screen. A paste into Terminal, a file with an Apple-sounding name, and a quiet connection out. Here is the whole sequence, and what you can check yourself.

Most people picture a compromised computer as something dramatic: A ransom note, a frozen screen. On a Mac in 2026 it usually looks like nothing at all. That's the point.

Here's the sequence we see most often, modeled on the macOS infostealer families that security researchers published analyses of this year.

1. Someone is talked into running a command

The most common way in isn't a clever exploit. It's a web page that says a download is broken, or a "verification" step, and asks the visitor to paste a command into Terminal. Microsoft documented a large campaign doing exactly this with fake macOS utilities. The command fetches a script and runs it. Because it arrived through Terminal rather than a browser download, macOS never adds the quarantine flag that triggers Gatekeeper's checks.

2. It makes itself at home, under an Apple-sounding name

Next, the malware sets itself up to survive a restart, usually by writing a LaunchAgent: A small file in ~/Library/LaunchAgents that tells macOS to start a program every time you log in. The file names are chosen to look boring. Jamf's analysis of CrashStealer describes one called com.apple.crashreporter.helper. SentinelOne found SHub Reaper posing as Google's software updater.

Apple's own background agents run Apple's own programs, from system folders. A "com.apple" agent that runs something from your home folder or Application Support is not Apple.

3. It collects, and it calls out

Then it does what it came for: Browser passwords and cookies, the macOS keychain, crypto wallets, SSH keys, cloud credentials. It sends them to a server the attacker controls, often over ordinary HTTPS, so the traffic blends in.

The whole thing can take less than a minute, and nothing on screen changes.

What you can check yourself

You don't need special tools to take a first look:

  • Open System Settings → General → Login Items & Extensions and read the list. Anything you don't recognize deserves a search.
  • In Terminal, run ls -la ~/Library/LaunchAgents and look at the names and dates. Be suspicious of anything named like Apple or Google that appeared recently.
  • Think back: Has anyone on your team pasted a command from a website into Terminal to "fix" something?

None of this is conclusive, and a careful attacker covers their tracks. But it's more than most small teams have ever looked at.

What changes with monitoring

In a monitored environment, each step above is a detection in its own right: A shell command fetched from the internet, a LaunchAgent impersonating Apple, a first-ever connection to an unfamiliar address. The response is automatic (suspend the process, quarantine the file, block the address) and it happens in seconds, at whatever hour it happens.

If you'd like to know whether any of this has already happened on your machines, that is exactly what a Compromise Assessment answers.

Further reading: Jamf on CrashStealer, SentinelOne on SHub Reaper, Microsoft on ClickFix lures targeting macOS.

Find out what is already on your machines.

We recommend starting with a one-week Compromise Assessment. $500 of it is credited if you continue into monitoring.