JSCoreRunner, also known as FileRipple, is a macOS malware family/campaign first identified in August 2025 and linked by Palo Alto Networks Unit 42 to cybercrime cluster CL-CRI-1089. It was distributed via malvertising and fake applications targeting Apple systems, and is described as the earlier stage or predecessor of the later FlutterShell malware used in Operation FlutterBridge. Unit 42 reported that FlutterShell shares JSCoreRunner’s core command structure, including functions for executing commands, reading files, and listing directories, indicating JSCoreRunner had backdoor capabilities for command execution and file-system interaction. Compared with FlutterShell’s dynamic remote logic-loading design, JSCoreRunner reportedly embedded its malicious logic statically in the binary. The activity is associated with the broader CL-CRI-1089 malvertising ecosystem, which has targeted macOS users and used fake Google ads and trojanized applications. High-confidence aliases and associations in the reporting identify JSCoreRunner as FileRipple and place it as a precursor to the Operation FlutterBridge/FlutterShell activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
However, from August 2025, the network shifted to Apple systems with a campaign known as JSCoreRunner, also called FileRipple.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
It gives attackers full remote control over the infected system, including the ability to execute commands... FlutterShell shares its core command structure with a previously documented macOS malware called JSCoreRunner, including functions for executing commands.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malware/campaign variant used by CL-CRI-1089 to target Apple systems before the later shift to FlutterShell.
A previously observed macOS malware campaign linked by researchers to FlutterShell and Operation FlutterBridge.
Previously documented macOS malware whose command structure overlaps with FlutterShell. It embedded its malicious logic statically in the binary and supported command execution, file reading, and directory listing.
A previously reported malware/activity cluster linked to the same threat activity as FlutterShell and attributed to CL-CRI-1089. It is described as an earlier stage in the evolution toward FlutterShell.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.