Threat researchers reported a renewed surge of Odyssey Stealer activity targeting macOS, with infections spreading rapidly across multiple regions. The malware is typically delivered via social engineering—masquerading as legitimate software updates, fake apps, or cracked tools—and is designed to steal high-value data including cryptocurrency wallets, browser-stored credentials (e.g., Chrome and Safari), personal documents, and items stored in the macOS Keychain. Moonlock Lab telemetry described a sharp increase in detections and a fast-expanding geographic footprint, consistent with a coordinated campaign and improved stealth/evasion techniques.
In parallel, analysis of Apple’s built-in malware defenses noted an unusual XProtect update (version 5327) that significantly expanded a newer YARA ruleset file, XPScripts.yr, focused on detecting malicious OSAScript (including AppleScript) content at execution time via the Open Scripting framework. The update increased OSAScript-focused rules from 2 to 14, reflecting growing abuse of lightweight, script-driven infection chains in recent macOS stealer campaigns (including AMOS/SOMA), where victims are coached into running obfuscated Terminal commands and downloading payloads (e.g., via curl) to avoid quarantine controls. Together, the reporting indicates escalating macOS infostealer pressure and corresponding defensive tuning by Apple to better detect script-based tradecraft used to bootstrap these infections.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
A new wave of Odyssey stealer activity targeting macOS users was publicly reported, aligning with broader observations of rapidly evolving infostealer campaigns against Apple systems.
Apple updated XProtect to version 5327, significantly revising XPScripts.yr and expanding its ruleset from 2 to 14 to better detect malicious OSAScript/AppleScript used in evolving macOS stealer campaigns.
By early 2026, AMOS/SOMA and related Odyssey-style macOS stealer activity was increasingly delivered through poisoned search results and other lures that tricked users into running obfuscated Terminal commands instead of relying on traditional exploit chains.
Apple added a newer Yara-based component, XPScripts.yr, to XProtect with version 5322, initially containing two rules to inspect OSAScript/AppleScript content for malicious behavior.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.