XProtect 5356 sharpens its YARA eye on Bundlore adware

Apple's weekly Mac malware-signature refresh lands at version 5356 with a tighter rule for the Bundlore adware family.

AppleThreat Staff
2 Min Read

Apple’s built-in Mac malware scanner rolled to a fresh build this week as part of the company’s routine weekly signature refresh for every supported version of macOS.

Released on August 18, the update moves XProtect to version 5356. Apple does not say what the refresh addresses, and changelogs compiled by third-party monitoring tools describe it as a modest one. The Osascript rules in XPScripts.yr carry no changes; the single revision sits in the YARA rule for MACOS.BUNDLORE.KUDU.3.

Bundlore is a long-running adware family that sneaks onto Macs inside software bundles and fake installer pages, often as a side effect of users grabbing apps from unofficial sources. The KUDU variant is one entry in a broader set of Bundlore signatures XProtect has carried for years, so the amendment likely tightens detection of a newer build rather than adding a brand-new family.

The signature data reaches Sequoia and later machines through iCloud and shows up in SilentKnight as XProtectPlistConfigData_10_15-5356. Users can check the installed version with the xprotect check command or force the refresh with xprotect update.

The weekly cadence has become Apple’s quiet workhorse against Mac malware. XProtect 5355 arrived on August 12 with rules for TimelineTurtle and new AppleScript malware, and 5354 targeted chat apps and crypto wallets a week earlier.

Share This Article