Apple removes popular anti-adware app Adware Doctor from the Mac App Store; the app surreptitiously stole and sent users' browsing history to a domain in China
Apple has removed a top Mac app called Adware Doctor, designed to “prevent malware and malicious files from infecting your Mac …
Context & Ripple Effects
Adware Doctor was one of the top paid utilities in the Mac App Store when researchers found it quietly uploading users' browsing history to a server in China — the discovery forced Apple's hand within a day. The removal fits a recurring pattern: Apple previously purged apps that installed root certificates to block ads (Been Choice and its peers in 2015) and apps built with the XcodeGhost-compromised toolchain.
What makes this episode escalate rather than close is what followed: within two days, [[a:933247|Trend Micro's Dr. Unarchiver — the 12th most popular free Mac app — was found harvesting the same kind of sensitive data]], suggesting Adware Doctor was not an outlier but one instance of a category problem among 'cleanup' utilities sold through Apple's own storefront.
First-order effects
- Users who installed Adware Doctor had their browsing history exfiltrated to a China-based domain, and Apple has cut off new downloads by pulling the app from the Mac App Store.
Second-order effects
- The takedown puts every top-ranked Mac security and cleaner utility under scrutiny — Trend Micro's suite, including Dr. Unarchiver, was caught doing the same within days, forcing other utility developers to defend their data practices or face removal.
Third-order effects
- Apple's curation is becoming the de facto malware defense for the Mac, but the model keeps leaking: two years later researchers found adware carrying Apple's own notarization, showing that signed-distribution pipelines can be abused even when the storefront itself polices listings.
- Because the stolen data flowed to a China-linked destination while Apple has also removed apps under pressure from Beijing (the Hong Kong protest-tracking app), App Store enforcement is increasingly read through a geopolitical lens, not just a security one.
The trend: Mac software distribution is consolidating around Apple's remove-and-notarize gatekeeping as the primary security control, with each breach — from XcodeGhost to notarized adware — testing whether a curated storefront can actually vouch for what it sells.