Apple updated its on-device macOS malware scanner for the second time in under a week as XProtect 5353 arrived on Tuesday with fresh detection capabilities targeting a family called TimelineTurtle.
The latest revision deploys YARA rules tuned to catch two previously unrecorded strains. It follows hard on version 5352 from last week, which focused on the BoatLoad malware family. Apple does not disclose what triggers each individual update, leaving researchers to reverse-engineer the signature files.
A macOS security researcher at The Eclectic Light Company spotted the new rules and noted they target variants labeled XOPADE and PACOPA. The update also tightens existing detection for OSASCRIPT.SYPR, a threat category that has appeared in earlier signature sets.
The accelerated pace of XProtect releases this month contrasts sharply with the pattern seen through early 2026, when weeks often passed between updates. That shift may reflect a busier macOS threat landscape or a policy change inside Apple’s security team to push detections faster.
Mac owners can verify the update by running sudo xprotect check in Terminal. If the response shows a version below 5353, sudo xprotect update forces an immediate refresh without waiting for the automatic iCloud distribution.