Episode Details
Back to Episodes
The Mac You Trust Runs the Code You Never See
Description
This story was originally published on HackerNoon at: https://hackernoon.com/the-mac-you-trust-runs-the-code-you-never-see.
Malicious npm packages bypass macOS defenses entirely. How supply chain attacks hit Mac developers, orgs, and everyday users — and why you're exposed.
Check more stories related to undefined at: https://hackernoon.com/c/undefined.
You can also check exclusive content about #npm, #supply-chain-attacks, #macos, #crypto, #infostealer, #developer-security, #npm-malware, #good-company, and more.
This story was written by: @moonlock. Learn more about this writer by checking @moonlock's about page,
and for more stories, please visit hackernoon.com.
Malicious npm packages are now one of the most active ways attacker code runs on a Mac — and they bypass Apple's defenses entirely, since an `npm install` script never faces Gatekeeper or notarization. It just runs as you. Landmark 2024–2026 attacks (Solana, the Nx "s1ngularity" breach, the 2.6-billion-download chalk/debug phish, the Shai-Hulud worm, North Korea's Keychain-targeting campaigns, and a RAT inside axios) prove the pattern is recurring. And you don't have to write code to be hit: developers lose their credentials and wallets, and everyday users lose funds when an app they trusted ships a poisoned dependency.