- Sources: SafeDep analysis
- Summary: SafeDep published an analysis on 2026-08-21 of one macOS implant recovered from a single compromised workstation. The chain begins with a click on an in-video YouTube advertisement dated 2026-07-26, passes through two attacker-owned redirect domains, and ends with the user running a package named as a TradingView installer. The implant gains root and intercepts HTTPS sessions through a rogue root certificate authority placed in the System keychain. The post describes the password capture both ways, once as a native dialog inside the trusted
Installer.app flow and once as a fake prompt shown during installation, and does not reconcile the two. SafeDep links the campaign to WEEVILPROXY and JSCEAL, and states that link as an inference from architectural and delivery overlap rather than as a confirmed attribution. SafeDep names no affected macOS versions anywhere in the analysis. It names four host artifacts: a LaunchAgent whose plist is com.microsoft.service.systemhelperwatcher.v8mgfk.plist, a payload directory at ~/Library/Application Support/.com.microsoft.service.systemhelperwatcher.v8mgfk/, a plaintext password cache at /Users/Shared/.passwd, and a local proxy listener on 127.0.0.1:49313. - Why it matters: Delivery was a paid placement on a mainstream ad platform, so the four named artifacts give defenders something concrete to hunt for on hosts where an ad-linked installer was run.
send feedback on this story