Every week Apple silently refreshes the malware signatures built into macOS, and this week’s update adds detections for a growing script-based threat family plus new AppleScript attack patterns. The company published no notes about what prompted the changes, as usual.
Independent Mac analyst Howard Oakley documented the refresh on Tuesday. The detection engine now sits at version 5355 and rolls out to every supported macOS release, arriving automatically through iCloud on Sequoia and newer builds. The Osascript list gains three new entries – MACOS.OSASCRIPT.TIWA, MACOS.OSASCRIPT.TILO and MACOS.OSASCRIPT.TIBUIN – and the existing MACOS.OSASCRIPT.SYPR rule was revised. YARA coverage of the TimelineTurtle family extends as well, with MACOS.TIMELYTURTLE.HCAGEX and MACOS.TIMELYTURTLE.HCAGPE added to its detection set.
TimelineTurtle is a familiar target for Apple’s signature pipeline. Version 5353 added rules for earlier variants of the family, and 5354 concentrated on protecting chat apps and crypto wallets. The steady stream of refreshes suggests the malware keeps evolving.
To confirm the refresh landed, open System Information and look under the Software section, or type “sudo xprotect check” in Terminal. Oakley notes that command still errors on macOS 27 Golden Gate, though “sudo xprotect update” should force the installation there. Because the rules ship to older operating systems too, even Macs on legacy releases receive the new coverage.