Researchers say version 2.92 of third-party BitTorrrent client Transmission, offered for a day for download from Transmission, was infected with OS X malware
Context & Ripple Effects
This is the second time in six months that Transmission's own download channel has been poisoned. In March, researchers found what Reuters called the first known ransomware aimed at Mac users hidden inside an infected Transmission build, which a Transmission rep later said had been downloaded about 6,500 times before Apple revoked the developer certificate that let it install.
The new report matters because it shows the March incident was not a one-off: a popular, trusted open-source client got compromised at the source again, and the same playbook would later hit another mainstream Mac utility when the HandBrake server was hacked and roughly half of its downloads over several days carried a remote access trojan.
First-order effects
- Anyone who downloaded version 2.92 from Transmission during the one-day window is exposed to OS X malware on their machine right now and needs to check and clean their system.
- Transmission faces an immediate trust crisis on top of its March ransomware episode — it must purge the infected binary, reissue a clean build, and explain to users why its official download channel failed twice.
Second-order effects
- Other widely distributed Mac utilities come under the same suspicion: the HandBrake compromise shows attackers have learned that hijacking a trusted project's server reaches more victims than any single exploit, so every popular Mac download page becomes a target.
- Users and IT teams start demanding verifiable integrity for third-party Mac software — checksums, signed builds, and mirror vetting shift from best practice to table stakes for projects like Transmission.
Third-order effects
- If the pattern holds, Mac malware economics move away from attacking Apple's OS defenses — as earlier work on fully patched OS X zero-days and firmware worms explored — toward poisoning the trusted distribution layer itself, where one compromised server outperforms any single vulnerability.
- That pushes responsibility for endpoint safety onto individual projects' operational security, raising the question of whether small open-source teams can sustain the signing and infrastructure hygiene that their distribution role now demands.
The trend: Attackers are shifting from exploiting Mac OS vulnerabilities to poisoning the trusted download channels of popular third-party applications, making software supply-chain integrity the new front line for Mac security.