Apple’s built-in macOS malware detector moved to version 5358 overnight, reaching every supported edition of the operating system. The refresh adds six YARA rules: four expand coverage of ShadyShoelace, a family only recently on Apple’s radar, under MACOS.SHADYSHOELACE.OSLOSTA, MACOS.SHADYSHOELACE.OSLODL, MACOS.SHADYSHOELACE.LODLSYDEAR and MACOS.SHADYSHOELACE.LODLSYDEX8, with MACOS.DUBROBBER.SAINDY and MACOS.DUBROBBER.CHREIM extending the older Dubrobber detections. As with every drop in the series, no notes explained what triggered it.
The AppleScript side of the scanner changed too. MACOS.ANGRYORB.JXPL and MACOS.OSASCRIPT.DUEXKE joined the XPScripts rule set, the SYPR detection was tightened, and MACOS.OSASCRIPT.ANMA came out.
Sequoia and newer versions pull the data from iCloud with nothing required of users. The update appears under Installations in System Information as XProtectPlistConfigData_10_15-5358; sudo xprotect update forces it, while the sudo xprotect check command still misbehaves on macOS 27.
Version 5357 landed a week earlier with ten rules aimed at AmnesiaStealer, keeping the near-weekly rhythm of automatic signature refreshes that quietly stack new protections on defenses for older Mac malware.