Kaspersky says a new MacSync macOS stealer variant, first spotted in the wild in September 2026, replaces the family’s earlier AppleScript-style droppers with compiled Objective-C and Swift modules. The same report says the infection chain also uses iCloud at one stage to pass the next payload.
That shift matters because the malware no longer looks like an obvious script launch or single-file dropper. Instead, it moves through normal-looking app and cloud behavior, which makes script-focused detection and simple file-hash checks easier to miss while the stealer and its backdoor chain run.
The result is a cleaner fit for the same ecosystem that already tolerates unsigned DMGs, cracked apps, and fake wallet software. For macOS teams, the exposure is not just one infected host but developer machines and crypto users that can hand the malware a more believable place to live.