The Mac You Trust Runs the Code You Never See

https://hackernoon.imgix.net/images/l7noBCUFwmcERrcGKL5jHUS0UcV2-8x83qzr.png

The blind spot

Ask the average Mac owner how malware gets onto their machine and you will hear a familiar mental model: you download a shady app, you ignore a Gatekeeper warning, you click something you should not have. Apple has spent more than a decade training users to think exactly this way, and its defenses (Gatekeeper, notarization, XProtect) are built around the same assumption: that danger arrives as a file you consciously choose to open.

Malicious npm packages break that assumption completely. They do not arrive as an app. They do not trip a Gatekeeper prompt. They are neither notarized nor un-notarized, because Apple’s trust system never looks at them. They arrive as a line in a dependency tree, often a line no human ever typed — and they run with your permissions the moment you type npm install. For a growing share of macOS users, this is now...

Copyright of this story solely belongs to hackernoon.com. To see the full text click HERE

Read more