XProtect jumps to 5360 with thirteen new detection rules

Apple's built-in malware list gains six YARA rules and seven AppleScript checks in a version bump that arrives with no explanation.

AppleThreat Staff
2 Min Read

A malware signature list that every Mac consults before it opens a file has grown again, and the additions lean on adware families and scripted installers rather than a single headline threat.

The refresh lifts XProtect to version 5360 across every supported release of macOS. Apple attached no note explaining the change, and version 5359 never shipped, which is why the jump looks wider than it is.

Scripted droppers dominate the new entries

Seven rules land in the AppleScript file XPScripts.yr, one of them written for a family tracked as AngryOrb. Two ageing ShadyShoelace entries were tidied in the same file.

Admins can confirm the drop by opening System Information and reading the Installations list under Software, where the payload appears as XProtectPlistConfigData_10_15-5360. SilentKnight and SystHist report the version on machines from El Capitan through Golden Gate.

Six YARA entries follow in the main signature list, covering Bonzai, LoathesomeLabelMaker, ShadyShoelace and a second AngryOrb variant, and several whitespace faults inside older rules were repaired.

Why a quiet version bump still matters

Signature data moves faster than operating system releases, so XProtect is often the first layer to react to a Mac strain that carries no CVE. Because Apple publishes no advisory with these updates, the rule names are the only public record of what the company is chasing.

One wrinkle matters for fleet teams. Macs on Sequoia or later may receive the file through iCloud rather than a software update, so a machine can run the new version while its update pane shows nothing at all.

Share This Article