I just googled it, actually.
The top result was [Flashback](
https://en.wikipedia.org/wiki/Trojan_BackDoor.Flashback).
Infected 600k at its height, but as of Jan 2014, there were only about 20k infected computers.
It redirected users to a compromised site, which used JS to load a Java applet containing an exploit that was already patched in the official Java, but not in the default version that comes pre-installed on Macs. The applet tricked you into installing "Flash" on your system.
- Adblock would've stopped the JS from executing in the first place
- We'd definitely have the latest Java versions
- I uninstalled Flash ages ago, and use Chrome's built in player instead, and certainly wouldn't install it from a site that isn't Adobe
Apple themselves have learnt from the incident, and have been speeding up Mac releases of pre-installed software since then.
The possible attack vectors against modestly capable Mac users are quite low..I simply don't see it happening. Unless I'm being targeted by institutional/state hackers. In which case I doubt AV would do much good.
Social engineering and poor passwords are likely to be a much bigger threat than malware.