Researcher finds a macOS adware campaign using malware notarized by Apple; after being notified, Apple shut it down, but then another notarized variant emerged
The ubiquitous Shlayer adware has picked up a new trick, slipping past Cupertino's “notarization” defenses for the first time.
WiredLily Hay Newman
Context & Ripple Effects
Shlayer is not a newcomer: Kaspersky attributed roughly 30% of all macOS malware detections in 2019 to the trojan, which spreads through fake app installs. What changed with this Wired report is the vector — for the first time, Shlayer variants carried Apple's own notarization seal, the credential Gatekeeper presents to users as proof an app has been vetted.
Apple's revocation killed the original notarized build, but the immediate emergence of a second notarized variant means every Mac user who trusts the notarization badge during install was exposed twice — and revocation only helps users who update before running the app.
Second-order effects
Adware operators now treat notarization as a hurdle to be re-cleared rather than a wall, forcing Apple to tighten scrutiny of developer-account submissions — friction that lands on legitimate developers whose apps wait behind the same review queue.
Each successful bypass raises the value of macOS-focused research and third-party endpoint tools, since the platform's built-in trust signals can no longer be treated as sufficient by enterprise buyers.
Third-order effects
If notarized malware keeps recurring alongside structural gaps like the unnotarized-apps flaw, Apple's 'curated platform equals safe' positioning erodes, pushing macOS toward the layered third-party security market Windows users have long taken for granted.
The trend: As Mac malware volume climbs — from Shlayer's dominance in 2019 to M1-native campaigns like Silver Sparrow — Apple's gatekeeping model is shifting from a single vetting gate to a continuous arms race with adversaries who iterate faster than revocations.
I don't understand how an application that was NOT submitted by Adobe as an installer for a DISCONTINUED product gets NOTARIZED! This doesn't instill confidence at all. https://twitter.com/...
Well, not malware .app but apps containing malicious adware code. Cat-and-mouse “games” by definition have fully functional cats and mice. With notarization, if a mouse slips through, the cat has a big red (inorganic!) mouse-terminating button it can hit even after the fact. http…
Great work by @patrickwardle. Lessons learned: 👾macOS is not immune to malware - you are probably underestimating this risk 📈Non-Windows threats are demonstrably on the rise 🛡️Stay ahead of the game: defend your non-Windows assets with the same rigour https://objective-see.com/..…
In February Apple began “notarizing” all macOS applications, in an attempt to weed out illegitimate or malicious apps. But the ubiquitous Shlayer adware has picked up a new trick, slipping past Cupertino's “notarization” defenses for the first time. https://www.wired.com/...
Apple: “Notarization gives users more confidence that [...] software [...] has been checked by Apple for malicious components.” @patrickwardle: “Hold my Kava”. https://objective-see.com/...
Two digital security researchers found a malware campaign disguised as an Adobe Flash installer that had code notarized by Apple and would run on Macs! 😳👀 https://techcrunch.com/...