More Mac malware from Google search
eclecticlight.co
eclecticlight.co
Publish through homebrew like a civilized person, please!
Disabling JS + bracketed paste seems to be the only good solution.
Btw OP article uses a weird setup, why would they use `bash -c "$(curl $(echo qux | base64))"` instead of just "curl | bash"
Any decent project should have a way to install without Homebrew. It's really not necessary.
It could be worse -- at least you didn't spend tens of thousands on a 2019 model Intel Mac Pro in 2023. (Yes, they still sold them, and owners of those will be SOL in 2028. That's probably the worst OS support story in recent Apple history, and it's for some of their most expensive machines)
But then again I'll get rid of the iMac Pro this year. I'll have technicians butcher it and salvage whatever they can from it -- I suspect only the SSD will survive -- and will then tell them to hollow it out and put an R1811 board inside it so I can use it as a proper standalone 5K screen. I don't care about Macs anymore, they limit me too much and I can't maintain multiple Linux machines just when I figure I would want to do something that Macs can't do (like experiment with bcachefs or ZFS pools and volumes and snapshots for my continually evolving backup setup).
I'll be decommissioning 40+ 2020 27" iMacs this year (i9-9900, 32 GB) and it's such a shame to see so many great displays and otherwise functional and plenty fast computers become, essentially, e-waste.
But I've learned my lesson. While Apple computer served me well from 2019 to 2026, macOS gets less and less usable for me and the bunch of things I want to be able to do on it only increases, and its appeal only decreases (not to mention the very justified OCD I get when I look at how much crap is running 24/7 on it!).
The iPhone stays, though I wonder for how long more. But the Mac will be on its way soon enough.
Sources:
That's the whole point. Paying someone for that thing you also know how to do so they can consider that problem solved and focus on the things they know how to do.
Oh way, that last part doesn't exist.
I think GP's issue is forcing the use of homebrew for what seems like a rather trivial install. Just make the binary easily downloadable. It's not like you can't open the curled script to see what it fetches and do it yourself. It's just that having to jump through this useless hoop is annoying.
My mac is running the latest version of Tahoe but I never liked homebrew. You can bet I won't install it just for one app.
Managing the install lifecycle with one set of commands for multiple apps is why I love Homebrew
Glad you get a similar experience with MacPorts.
I'd classify that as an Apple problem rather than a Homebrew problem. If Apple themselves cannot be arsed to support an OS version, why would a volunteer project take on such a challenge?
For every piece of software I've fetched using Homebrew, there's a "compile from source" option available on Github or some other source repo.
Seems like good enough a reason for them not to do it.
Their tooling is open-source, surely the few people still using unmaintained versions of macOS can create a `LegacyHomeBrew/brew` repository with patches for old macOS versions? It would also be a good place to stuff all the patches and workarounds that may be necessary to support old macOS versions.
If you really want, you may be able to upgrade the OS anyways with https://github.com/dortania/OpenCore-Legacy-Patcher.
Or use Homebrew on the old OS with TigerBrew (https://github.com/mistydemeo/tigerbrew), but people online suggest MacPorts, not only because it has first-party support but also because it’s apparently better designed.
I also do not prefer to use these for the last 16+ years, and not planning to do so.
How old was it? With macOS "running an old version" is not really a viable or advisable path beyond a certain point. Might be something people want to do, might it a great option to have, but it's not very workable nor supported by Apple and the general ecosystem.
>Any decent project should have a way to install without Homebrew. It's really not necessary.
We don't install homebrew because it's necessary, but because it's convenient. No way in hell I'm gonna install 50+ programs I use one by one using the projects' own installers.
Besides, if "Homebrew dropped support" is an incovenience, "manually look for dozens of individual installers or binaries, make sure dependencies work well together, build when needed, and update all that yourself again manually" is even more of an inconvenience. Not to mention many projects on their own drop support for macOS versions all the time, or offer no binaries or installers.
The ubiquity of Homebrew continues to confound me.
At the very least, replace homebrew with something like devbox which has `devbox global` for globally managing packages, it uses nix under the hood, and it's probably the simplest most direct replacement for homebrew.
[1]: https://saagarjha.com/blog/2019/04/26/thoughts-on-macos-pack...
It's not a "system" package manager, nor was it ever meant to be. Its supplemental. I've also found it valuable on the various immutable linux distros.
Codex, Claude Desktop, etc etc all starting out as "macOS exclusive" feels so silly when they're targeting programmers. Linux is the only OS a programmer can actually patch and contribute to, and yet somehow we've got a huge number of developers who don't care about having a good package manager, don't care about being able to modify their kernel, don't care about their freedom to access and edit the code of the software they rely on to work...
It's depressing how much of the software industry is just people on macbooks using homebrew to install a newer version of bash and paying $5 for "magnet" to snap windows to the corners since their OS holds them in a prison where they can't simply build themselves a tiling window manager in a weekend.
The OS is core to your tools and workflows, and using macOS cedes your right to understand, edit, and improve your OS and workflows to a company that is actively hostile to open source, and more and more hostile to users (with a significant increase in ads and overly priced paid services over the years).
Anyway, yeah, homebrew sucks. At least nix works on macOS now so there's an okay package manager there, but frankly support for macOS has been a huge drag of resources on the nix ecosystem, and I wish macOS would die off in the programming ecosystem so nix could ditch it.
I admit I love the mbp hardware, but I can't stand macos anymore. So when my work computer was up for replacement, I didn't think twice and went with a PC, the latest thinkpad p14s. Everything works out of the box on Linux.
Is it as nice as a mac? No, especially the plastic case doesn't feel as nice under the hands as a mac's aluminum, the touchpad is quite good but worse than a mac's, and there are some gaps around the display hinge. But the display itself is quite nice (similar resolution, oled, although not as bright as a mac's), it's silent and it's plenty fast for what I do. I didn't pay for it, so I don't directly care about this point in this situation, but it also cost around half of what an equivalent mbp would have cost.
I also haven't tried the battery life yet, but it should hold at least as well as my 5-yo hp elitebook, which still held for around 5 hours last year. I basically never use it for more than an hour unplugged, so battery life is low on my priorities.
A macbook air is 1.25kg, and my thinkpad is 910g, and I can really feel that difference. The thinkpad keyboard also feels ever so slightly better too... and Linux working well is worth more than pretty much anything else.
It's ok, Apple knows this and will lock it's OS down to an iPhone like OS step by step until you're boxed in a nice little prison, and you'll accept it.
Also you'll pay them 30% on every transaction you do on said computer.
And I also hate what modern Macos is heading towards. I'm still ignoring/canceling the update on both my devices for the new "glass" interface.
And a thinkpad running Linux is just not doing it for me. I want my power efficient mac hardware.
Truth be told I just want to have my mbp running Linux. But right now it's not yet where it needs to be and I am most certainly not smart enough to help build it :(
I'm using a decade old thinkpad running linux and it is definitely 'doing it for me'. And I'm not exactly a light user. Power efficient mac hardware should be weighed against convenience and price. The developer eco-system on Linux is lightyears ahead of the apple one, I don't understand why developers still use either Windows or the Mac because I always see them struggle with the simplest things that on Linux you don't even realize could be a problem.
Other OSs feel like you're always in some kind of jailbreak mode working around artificial restrictions. But sure, it looks snazzy, compared to my chipped battle ax.
Are you talking about the battery? I bought a T16 AMD a month ago with the 86Wh battery and it lasts between 8 and 12 hour depending on the usage. Not as much as a macbook but enough to not worry too much about it. New intel ones are supposed to be much better on power efficiency.
It's off course one level bellow on the mac on that regard (and others maybe too), but if you want to use linux I think the trade-off is worth it.
The graphics story on Linux also sucks. I recently tried to convert my Windows gaming machine to Linux (because I hate W11 with a burning passion). It does work, but it’s incredibly painful. Wayland, fractional scaling, 120+ Hz, HDR. It’s getting better thanks to all the work Valve etc are putting in, but it’s still a janky messy patchwork.
MacOS just works. It works reliably. Installing things is easy. Playing games is easy. I’m able to customize and configure enough for my needs. I love it and I hope it sticks around because there is no way in hell I would move my work machines over to Linux full time.
What's wrong with those? I don't have a single screen which does 120 Hz + HDR, but I'm typing this on a 120 Hz laptop, with variable refresh rate, at 125% scaling, and everything works great with Plasma (haven't tried anything else). I also have an external HDR screen, but it only does 60 Hz. It works great, too, doing HDR on it but not on the laptop screen (running at the same time, of course). They also run at different scaling (125% and 100%).
Now I don't know how to confirm that VRR is actually doing anything, but I can tell there's a difference between setting the monitor to 60 and to 120 Hz. HDR on the other screen also produces a clear difference.
This is all running from integrated intel graphics, maybe with other GPUs it's more of a crapshoot, no idea.
Is it really a sin to pay for software to augment your OS? Like programmers make their living selling that and it’s horrible?
I'm writing software for Linux myself and I know that you run into weird edge case windowing / graphical bugs based on environment. People are reasonably running either x11 or wayland (ecosystem is still in flux in transition) against environments like Gnome, KDE, Sway, Niri, xfce, Cinnamon, labwc, hyprland, mate, budgie, lxqt, cosmic... not to mention the different packaging ecosystem.
I don't blame companies, it seems more sane to begin with a limited scope of macOS.
Alternatively, you could do development in a container and use apt-get there. That's probably safest now that we're using coding agents.
i.e. Let's say you install a bunch of homebrew packages, everything is working. Then 6 months later you go to install another package - homebrew likes to upgrade all your packages (and their dependencies) willy nilly.
And if it breaks shit, there's no way to downgrade to a specific version. Sometimes shit broke because the newer package is actually a broken package, or sometimes it's because the dev environment was depending on a specific version of that package.
There's basically no way to have multiple versions of the exact same package installed unless they use their hacky workaround to create additional packages with the version number included in the package name.
The UNIX in macOS is good enough for my needs, and I manually install anything extra that I might require.
/bin/bash -c "$(curl -fsSL https://raw.githubusercontent.com/Homebrew/install/HEAD/inst...)"
Then it prompts user for admin previledges. Also, it does not support installing as a local non-admin user.
You can install it via a .pkg here: [0]
Why does anyone trust that project to understand security?
How does that model work with distros like debian, where they freeze package versions and you might not get claude code until 2027 (or whenever the next release is)?
1. Create your own apt repository with newer software, and install from that. It's easy to package things, you can share the repository with trusted friends, running linux with friends is fun.
2. You can switch to a distro, like NixOS or Arch, which values up-to-date software more than slow stable updates.
Debian does seem to be more aligned with mailservers and such, where updates can be slow and thoughtful, not as much with personal ai development boxes where you want the hot new ai tool of the week available asap.
... Either way, learning to package software correctly for your distro of choice is a good idea, it's fun to bang out a nix expression or debian package when you need to install something that's not available yet.
I would love for folks to start packaging their software for major distros if for no other reason than to see just how annoying the tooling is to use.
In principle you could even make such a repository, or otherwise promote one.
Are there actually viable alternatives to the default debian repo? At best there's repositories run by various projects, but that's basically the same as level of security as "run a random binary you downloaded off the internet". The only plausible way that package managers increase security is through curation. If you're just blindly adding whatever repo to get some software installed, you're back at square one.
> It's not really any different than downloading a binary from a website, which we've been doing for 30 years.
The two are very different, even though some ecosystems (such as PHP) have used the "curl | bash" idiom for about the same amount of time. Specifically, binary downloads from reputable sites have separately published hashes (MD5, SHA, etc.) to confirm what is being retrieved along with other mechanisms to certify the source of the binaries.
Still doesn't address the fact that keys can be stolen, people can be tricked, and the gigantic all-consuming issue of people just being too lazy to go through with verifying anything in the first place. (Which is sadly not really a thing you can blame people for, it takes up time for no easily directly discernable reason other than the vague feeling of security, and I myself have done it many more times than I would like to admit...)
This implies an attacker controlling the server having the certificate's private key or the certificate's private key otherwise being exfiltrated (likely in conjunction with a DNS poisoning attack). There is no way for a network client to defend against this type of TLS[0] compromise.
I don't know if developer utilities can be distributed through the app store, but they should be so that Apple can review them properly. Criticisms aside, the iOS App Store and the iOS security model has been the best thing for software security (especially for lay-people), ever.
They can’t stop themselves from tightening their grip ever tighter, and always want to ensure you have no functionality above what they deemed sufficient.
Apple taking over Homebrew would be a disaster.
All the homebrew packages have checksums and are versioned in git, so if the upstream website is compromised and a malware installer is put in place of the package, `curl | bash` will just install the malware, while `brew` would start erroring out and refuse to install after downloading something with a different checksum.
You also get an audit log in the form of the git repo, and you also ensure everyone's downloading the same file, since `curl | bash` could serve different scripts to different IPs or user-agents.
I don't think brew does proper build sandboxing, so like `./configure.sh` could still download some random thing from the internet that could change, so it's only a bit better.
If you want proper sandboxing and thus even more security, consider nix.
A truly civilized person would use Linux, OpenBSD, etc, a free operating system where they may contribute fixes for their fellow man without having to beg at the boots of the single richest company on the planet with radar numbers asking for fixes from on high.
They cut support for old platforms way to fast and just in essence try to dictate far too much.
I am unfamiliar with the Apple ecosystem, but is there anything special about this specific app that makes it trustworthy (e.g: reputable dev, made by Apple, etc.)? Looking it up, it seems like an $8 app for a link unshortener app.
In any case, there have been malicious sites that return different results based on the headers (e.g: user agent. If it is downloaded via a user-agent of a web browser, return a benign script, if it is curl, return the malicious script). But I suppose this wouldn't be a problem if you directly inspect and use the unshortened link.
> Terminal isn’t intended to be a place for the innocent to paste obfuscated commands
Tale as old as time. Isn't there an attack that was starting to get popular last year on Windows of a "captcha" asking you to hit Super + R, and pasting a command to "verify" your captcha? But I suppose this type of attack has been going on for a long, long, time. I remember Facebook and some other websites used to have a big warning in the developer console, asking not to paste scripts users found online there, as they are likely scams and will not do what they claim the script would do.
---
Side-Note: Is the layout of the website confusing for anyone else? Without borders on the image, (and the image being the same width of the paragraph text) it seemed like part of the page, and I found myself trying to select text on the image, and briefly wondering why I could not do so. Turning on my Dark Reader extension helped a little bit, since the screenshots were on a white background, but it still felt a bit jarring.
The GitHub links are one of the nastiest Malware I ever encountered in my life!
I steals your Apple Keychain, all your "Safe" Passkeys, your Google Chrome "Saved Passwords", even your KeePass Database!
Login and security is still not sufficiently solved with attack-proofs for the most important things in life like your Bank, Email, Wallets, Social Logins.
Your "logged-in Sessions" also get stolen! It's unbearable that most cookies expire in months "ON THE SERVER SIDE"! You have no control and can't log the attacker out!
It happened to me, when I was in China and searched for ExpressVPN, because the main website didn't load forever, the GitHub link seemed like an alternative.. damn.. I changed my Google Password 5 times and the attacker was still able to log-in, it was so devastating! I had to change my email passwords multiple times too.
Sessions are what make logins valid and this is the weakest link of all. I wish Sessions used Off-The-Record encryption with One-Time-Pads, such that each acccess requires a new key, that can only be derived with a valid reply that makes safe that the attacker can be logged out safely.
https://github.com/rumca-js/Internet-Places-Database
I start with it, to find stuff I know. If there is stuff I don't know and is important to me, I add it to my database.
Also it enforces me to verify each link I visit. So links I visit are mostly ok.
Though I sometimes use chatgpt for instructions, and if someone poinsed the well "well enough" it might spread malware.
From what understand of MoltBot, I would expect it to ask for a lot of permissions. I guess maybe they are prompted closer to configuration time in the actual app.
A day later my parents called me very stressed out about a popup on my mother’s iPhone saying she had been hacked. I asked them to take a screenshot, and again it was a website that was styled to look like a modal on top of a iOS Settings app page. With the new ui this was extremely effective, as the page title is just a tiny thing down the bottom in scrolled state.
I don’t know what is going on, but I’d assume the problem is AI moderation.
https://www.securityweek.com/malvertising-campaign-abuses-go...
Basic hygiene is very simple: never run as Administrator. Create and use a regular user or poweruser group user. It's similar to a regular linux practice. Use Administrator account when needed only.
If you trust yourself to not blindly click OK on every UAC prompt, a single user account in the admin group is fine.
It's not enabled by default, though. Enabling it by default would probably break just about every Windows program out there and like UAC on Vista, everyone would turn it off immediately.
Computer asks for password. I type in password.
Admin access prompts are honestly a joke even on macOS. The source is completely opaque.
[0] https://developer.apple.com/library/archive/documentation/Se...
[1] https://learn.microsoft.com/en-us/windows/win32/secauthz/man...
Windows implements ACLs in a far more granular way than macOS and most other Unicies, however (with the exception of Slowaris).
Convincing a Linux user to paste rm -rf / into the terminal is not malware. It's social engineering.
Scanning binaries for known malware is already built into the OS.
In this case, the user is warned that the command wants to do something dangerous and must manually allow or deny the action.
Gatekeeper and Xprotect are good, but there's only so much they can do.
Clearly it isn't. XProtect is a joke. It's 2004-era ClamAV level of protection.
The screenshots from the article clearly show a permission prompt for a program. Whether that's a binary or a shell script or something else doesn't matter, the infection stage should've been caught by anti malware rather than permission prompts.
Windows Defender does this already. If Apple's AV can't catch this, I think they may be relying on their DRM-as-a-security-measure (signatures, notarisation, etc.) a bit too much.
I do occasionally use an app to clean somebody’s Mac of an irritating browser search hijack. I’ve never seen anything else.
Why should I change my mind?
If you prepare a ligit-looking web page where you instruct people to download and run malware, we'd better learn more on security and caution before blindly follow those directions.
Why should it be Google's (or Bing's) duty to filter those out?
Google intentionally disguises ads as search results, and even lets advertisers present a fake URL. When the system's purpose is to profit from tricking inattentive users, I think they should take on some liability for the outcome of what they're tricking people into doing.
Not to say that better teaching security isn't also a good idea.
The answers are in the question.
Beyond result quality it's absurd that it took LLMs to get meaningful natural language search. Google could have been working on that for many years, even if in a comparably simple manner, but seemingly never even bothered to try, even though that was always obviously going to be the next big step in search.
My point is, this is not solved by AI answers.
You had to disable permissions or approve some of that.
> Obviously there was a solution, probably an easy one, but I didn’t even look for it
It's hard to take this seriously. It's the most obvious setting possible. Settings > Privacy & Security > Full Disk Access > tick the apps you want to have it.
What's even the complaint here? That Mac has solid app permissions, but you can't be bothered to open the settings?
I also said it was the “final straw”. No worries at all if you’re not familiar with that expression. It means that there were lots of similar slights previously, and that the event I mentioned, while minor, was the one that finally pushed me to make the decision I made.
This sort of patronizing assholery is childish and unbecoming. Your comment would've been better without it.
> you can't be bothered to open the settings?
This kind of crap ticks me off and makes me respond in kind. I should be better, sure, but sometimes I'm not.
> This kind of crap ticks me off and makes me respond in kind. I should be better, sure, but sometimes I'm not.
I think we're all struggling to identify any other possible interpretation of, and I quote, "obviously there was a solution, probably an easy one, but I didn’t even look for it". Your words are not ambiguous - you knew this would be an easy issue to solve, and you did not bother trying to solve it. And you say this as though it's someone else's fault.
Should Tim Apple come to your desk personally every morning and ask which MacOS defaults it would suit you to remove? Are we to understand that the obvious security benefits of sandboxing filesystem access pale in comparison to any inconvenience for you, even if that inconvenience is you merely having to bother to open the settings?
You're being totally unreasonable, and you're acting mean when your unreasonableness is picked up on. Learn to take a note, particularly when you're in the wrong, rather than becoming an irrationally defensive ball of spittle and venom. It'll serve you better in the long run.
> rather than becoming an irrationally defensive ball of spittle and venom
Dude, maybe take your own advice?
I was possibly being too subtle, but my POINT is that MacOS has turned into a nanny state OS that is not suitable for professional use. You can't install packages that aren't from the App Store without jumping through hoops. And Gods help you if they aren't signed with a key blessed by Time Apple. You can't even use a terminal without granting is special permission. AGAIN, straw that broke the camel's back. You keep focusing on the straw and not the back of the poor camel.
I was also able to use sudo to remove /opt/homebrew afterwards.
And then there's also Apple which won't allow functional web apps, lest it affects their app store 30% cut.
If you want to trash your system I believe nothing prevents you from giving Firefox full-disk access.
Would do wonders for that mythical year of the linux desktop...