A new piece of Mac malware asks for the administrator password, then stores it where nobody would think to look: inside a settings file, written in characters that occupy no width on screen.
Jamf Threat Labs, which stumbled on the family while monitoring executables in VirusTotal, calls it CloudSyncD after the daemon its second stage runs under. A sample appeared on September 15, 2026, and within two days the researchers found builds wired to live command-and-control infrastructure.
Delivery is a disk image that mounts as a volume named Zoom. It shows the usual installer layout, but the background art walks the victim through System Settings and the Open Anyway button, the manual override that lets an ad-hoc signed bundle past Gatekeeper. A prompt then demands the login password and will not continue until the credential validates against the local account.
The captured password lands in a decoy file at ~/.config/zoom/data.json, dressed up as ordinary preferences with a theme, a language and a notifications flag. The secret itself is base64 encoded and buried inside the cache value under random filler. The offset and length needed to retrieve it hide in the neighboring version field as 48 zero-width Unicode characters, and the padding changes every run, so the offset never repeats.
The dropper carries its second stage internally, first trying a fileless launch through /dev/fd, then falling back to a temporary file on disk. The embedded implant surveys the host and accepts tasking as Mach-O binaries or tar archives, so the giveaway is an unexpected executable rather than suspicious shell activity. Both stages accept any TLS certificate they are offered.