Clankerusecase
macOS detection coverage
← Back to main site
Home/ Targets/ macOS

macOS detections

Clankerusecase tracks 66 detection use cases covering the macOS attack surface across 53 MITRE ATT&CK techniques.

Detections targeting macOS endpoints — osascript / launchd / .plist persistence / Mach-O execution.

Open Detection Library → View on the matrix
66Use cases
53Techniques
32Articles
5Kill-chain phases

Top techniques on macOS (25)

Delivery (9)

[WEEKLY] Brand-Impersonation Domain Fetch Followed by User-Context Loader Within 10 Minutes Internal delivery · alerting DSPDD [WEEKLY] Cross-Platform ClickFix Paste-to-Pipe Loader (UI-Parent Shell with Decode-and-Execute Payload) Internal delivery · alerting DSΣP [LLM] Malicious @velora-dex/sdk (9.4.1/9.4.2) pulled into GitHub Actions build runner Bespoke delivery · alerting DSΣPDDCS [LLM] Compromised @velora-dex/sdk npm package (9.4.1/9.4.2) installed on CI runner Bespoke delivery · alerting DSΣPDDCS [LLM] OpenClaw paste-site (rentry.co/glot.io) curl-pipe-bash semantic-hijack dropper Bespoke delivery · hunting DSΣPCS [LLM] node process spawning bash/curl chain to fetch Velora DEX install.sh dropper Bespoke delivery · alerting DSΣPDDCS [LLM] IoliteLabs VSCode extension dropper: VS Code child process reaching rraghh.com / oortt.com C2 Bespoke delivery · alerting DSΣPDD [LLM] npm/node postinstall hook spawning interpreter and reaching new C2 host (Axios-style dropper) Bespoke delivery · hunting DSPDDCS [LLM] Pastebin-piping stager retrieved from rentry.co/openclaw-core (macOS/Linux ClawHub skill) Bespoke delivery · alerting DSPDDCS

Exploitation (15)

[LLM] npm/node install-time payload: package manager spawning curl/launchctl/osascript on a runner Bespoke exploit · hunting DSΣPCS Article-specific behavioural hunt — A Forgotten Contributor Account Compromised the Entire Mastra npm Package Scope Bespoke exploit · hunting DSP Article-specific behavioural hunt — Pythagora-io/gpt-pilot Compromised on GitHub - Shai-Hulud Credential Stealer Blo Bespoke exploit · hunting DSP Article-specific behavioural hunt — Nx Console VS Code Extension Compromised Bespoke exploit · hunting DSP Article-specific behavioural hunt — Mini Shai-Hulud Hits AntV: 300+ Malicious npm Packages Published via Compromised Bespoke exploit · hunting DSP Article-specific behavioural hunt — TeamPCP's Mini Shai-Hulud Is Back: A Self-Spreading Supply Chain Attack Compromi Bespoke exploit · hunting DSP Article-specific behavioural hunt — TanStack Npm Packages Compromised Inside The Mini Shai Hulud Supply Chain Attack Bespoke exploit · hunting DSP Article-specific behavioural hunt — @velora-dex/sdk Compromised on npm: Malicious Version Drops macOS Backdoor via l Bespoke exploit · hunting DSP Article-specific behavioural hunt — axios Compromised on npm - Malicious Versions Drop Remote Access Trojan Bespoke exploit · hunting DSP Article-specific behavioural hunt — Malicious IoliteLabs VSCode Extensions Target Solidity Developers on Windows, ma Bespoke exploit · hunting DSP Article-specific behavioural hunt — Axios npm Package Compromised: Supply Chain Attack Delivers Cross-Platform RAT Bespoke exploit · hunting DSP Article-specific behavioural hunt — axios compromised on npm: maintainer account hijacked, RAT deployed Bespoke exploit · hunting DSP Article-specific behavioural hunt — Harden Runner Now Supports Windows and macOS GitHub Actions Runners Bespoke exploit · hunting DSP Article-specific behavioural hunt — Installing and managing Java on macOS Bespoke exploit · hunting DSP Article-specific behavioural hunt — Using insecure npm package manager defaults to steal your macOS keyboard shortcu Bespoke exploit · hunting DSP

Installation (28)

[WEEKLY] Internet-Facing Service Process Spawning Unix Shell or Ingress-Tool LOLBin (Edge Zero-Day Post-Exploit) Internal install · alerting DSΣPDD [LLM] SleeperGem Unix persistence: cron/systemd/LaunchAgent write by Ruby-descended shell Bespoke install · hunting DSΣPDDCS [LLM] Velora macOS backdoor launchctl persistence (com.apple.Terminal.profiler.plist) Bespoke install · hunting DSΣPCS [LLM] MiniRAT launchctl persistence established during macOS CI build Bespoke install · hunting DSΣPCS [LLM] plain-crypto-js postinstall RAT dropper spawns downloader (axios/Sapphire Sleet) Bespoke install · alerting DSΣPDDCS [LLM] axios RAT dropped artifacts: renamed PowerShell wt.exe + campaign 6202033 files Bespoke install · alerting DSΣPDDCS [LLM] IronWorm cross-platform payload execution by SHA256 (jscrambler stealer binaries) Bespoke install · hunting DSΣPDDCS [LLM] Jackson typosquat Cobalt Strike implant hash sighting (Win + macOS/Linux) Bespoke install · hunting DSΣPDDCS [LLM] easy-day-js implant artifacts dropped: protocal.cjs / NodePackages / cross-OS persistence files Bespoke install · alerting DSΣPDDCS [LLM] cluw macOS stealer shell dropper fetching payload from ClawHavoc/AMOS C2 IP Bespoke install · hunting DSΣPCS [LLM] cluw infostealer and malicious ClawHub skill payload hashes on macOS Bespoke install · hunting DSΣPCS [LLM] macOS.Gaslight LaunchAgent persistence masquerading as com.apple.system.services.activity Bespoke install · alerting DSΣPCS [LLM] macOS.Gaslight self-staged standalone CPython 3.10.18 fetch (astral-sh python-build-standalone) Bespoke install · alerting DSΣPCS [LLM] macOS.Gaslight known-bad file hashes (Mach-O implant, BONZAI sibling, Python/bash stages) Bespoke install · hunting DSΣPCS [LLM] easy-day-js stealer persistence masquerading as Node tooling (NodePackages / LaunchAgent / systemd) Bespoke install · alerting DSΣPDDCS [LLM] macOS LaunchAgent Persistence — com.user.kitty-monitor.plist (Nx Console Compromise) Bespoke install · alerting DSΣPDDCS [LLM] Kitty cat.py Python Backdoor File Drop / Execution (Nx Console Compromise) Bespoke install · alerting DSΣPDDCS [LLM] Mini Shai-Hulud 'gh-token-monitor' persistence daemon (LaunchAgent / systemd) Bespoke install · alerting DSΣPDDCS [LLM] macOS LaunchAgent/LaunchDaemon plist persistence pointing at Python interpreter Bespoke install · hunting DSΣPDDCS [LLM] macOS Python backdoor persistence via kitty-monitor LaunchAgent and cat.py drop Bespoke install · alerting DSΣPDDCS [LLM] launchctl persistence registering zsh.profiler service from non-admin location Bespoke install · alerting DSΣPDDCS [LLM] macOS file write of profiler binary to com.apple.Terminal masquerade path Bespoke install · alerting DSΣPDDCS [LLM] OpenClaw persistence — launchd plist / systemd unit drop referencing 'openclaw' Bespoke install · alerting DSΣPDDCS [LLM] TeamPCP telnyx FetchAudio() — python subprocess running inline base64 exec Bespoke install · alerting DSΣPDD [LLM] macOS Axios RAT daemon spoof + ad-hoc codesign of hidden /private/tmp binary Bespoke install · alerting DSΣPDDCS [LLM] axios RAT artifact dropped: com.apple.act.mond / wt.exe / ld.py with known SHA256 Bespoke install · alerting DSΣPDD [LLM] npm postinstall SSH-backdoor chain: node spawning sudo ufw allow 22/tcp + chown ~/.ssh Bespoke install · alerting DSΣPDD [LLM] PTX-Player macOS infostealer artifacts (SHA256 + dropped /private/tmp logs) Bespoke install · hunting DSΣPCS

Command & Control (3)

[LLM] Build runner beacon/exfil to Velora backdoor C2 (89.36.224.5 / datahub.ink) Bespoke c2 · hunting DSΣPDDCS [LLM] macOS.Gaslight Telegram Bot API C2 polling from non-browser process Bespoke c2 · hunting DSΣPCS [LLM] Outbound connection to Velora DEX npm supply-chain C2 89.36.224.5 Bespoke c2 · alerting DSΣPDDCS

Actions on Objectives (11)

[WEEKLY] Non-Browser Process Reads Browser Credential / Cookie SQLite Then Egresses to Public Destination Within 10 Minutes Internal actions · alerting DSPDD MCP Filesystem Server Suspicious Extension Write ESCU actions · hunting P File Download or Read to Pipe Execution ESCU actions · alerting P MacOS AMOS Stealer - Virtual Machine Check Activity ESCU actions · hunting P MacOS Gatekeeper Bypass ESCU actions · hunting P MacOS Hidden Files and Directories ESCU actions · hunting P MacOS List Firewall Rules ESCU actions · hunting P [LLM] macOS BlueNoroff stealer exfiltrating to Telegram bot (Aurora channel) Bespoke actions · alerting DSΣPCS [LLM] macOS.Gaslight keychain theft + collected_data.zip staging Bespoke actions · alerting DSΣPCS [LLM] Developer credential store read by Python or Node spawned from VS Code (Nx Console stealer pattern) Bespoke actions · hunting DSPDDCS [LLM] macOS Text Replacements exfiltration via `defaults read NSUserDictionaryReplacementItems` Bespoke actions · alerting DSΣPCS

Recent articles citing macOS-targeted detections