XProtect 5354 walls off chat apps and crypto wallets

Apple's weekly XProtect refresh adds a new policy layer that shields chat apps, browsers, and crypto wallets.

AppleThreat Staff
2 Min Read

Apple pushed its weekly XProtect refresh to version 5354 on August 5, and this one is bigger than the usual signature bump. The update adds a brand new file called AppProtectionPolicy.plist that defines which third-party apps get protected status, organized by allowed Team and Signing IDs across categories that include chat clients, browsers, and crypto wallets.

Apple also slipped in a single new YARA rule for a family it calls MACOS.NEFARIOUSNAPKIN, while leaving the Osascript rules in XPScripts.yr untouched. As always, the company offers no public notes on what triggered the update, so the exact malware the rule targets is unknown. The XProtectRemediator data files were not part of this refresh.

The AppProtectionPolicy addition matters more than the YARA rule. It signals that Apple is broadening XProtect from a pure malware detector into a policy layer that can shield categories of sensitive applications, with crypto wallets being the most notable inclusion. Given the recent wave of Mac wallet-drainer campaigns spread through fake browser updates and sponsored search ads, extending system-level protection to wallet apps is a timely hardening move.

The update reaches all supported macOS versions, from older releases through Tahoe and the Golden Gate beta, and installs silently via iCloud on Sequoia and later. Users can confirm it landed by checking System Information, selecting Installations, and looking for XProtectPlistConfigData at version 5354, or by running sudo xprotect check in Terminal.

Share This Article