Attackers compromised MacUpdate and distributed trojanized versions of popular macOS applications including Firefox, OnyX, and Deeper, replacing legitimate downloads with installers that deployed a cryptocurrency miner. Researchers reported the malware as OSX.CreativeUpdate / OSX.CreativeUpdater, noting that the fake installers were built with Platypus, used decoy applications to reduce suspicion, and in some cases exposed operational mistakes when those decoys failed to launch properly.
Once installed, the malware established persistence through LaunchAgents and ran under a malicious sysmdworker process that ultimately launched minergate-cli to mine Monero via connections to minergate.com. The campaign also relied on deceptive infrastructure, including lookalike domains such as titaniumsoftware.org and download-installer.cdn-mozilla.net, while hosting payloads on public.adobecc.com, underscoring the risk posed by compromised software distribution channels and third-party download sites for macOS users.

Trace attribution and downstream blast radius.
3 events from the most recent confirmed update back to the earliest known activity.
Objective-See published follow-on analysis of the MacUpdate-delivered macOS malware, adding technical detail to the already disclosed campaign. This represents a later research update rather than a separate incident.
On February 1, 2018, researchers reported that the MacUpdate compromise was being used to spread macOS cryptomining malware with persistence via LaunchAgents and a malicious sysmdworker process. Public reporting also identified related infrastructure, including lookalike domains and payload hosting used in the campaign.
Attackers breached the MacUpdate website and served malicious versions of Firefox, OnyX, and Deeper to macOS users. The trojanized installers delivered a Monero-mining malware later dubbed OSX.CreativeUpdate/OSX.CreativeUpdater.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.