Research showed that Apple’s built-in tclsh interpreter on macOS can be abused as a living-off-the-land binary to fetch and execute shellcode entirely in memory, avoiding normal file-based defenses. The technique relies on tclsh entitlements including com.apple.security.cs.allow-unsigned-executable-memory and com.apple.security.cs.disable-library-validation, which permit unsigned executable memory and loading unsigned dynamic libraries without standard code-signing enforcement; the report also noted that Tcl ships with the Ffidl library and HTTP/TLS support, enabling native calls such as mmap, memcpy, and mprotect and remote payload retrieval over HTTPS.
The findings indicate that tclsh is also listed in XNU hardening exceptions, placing it in a keys-off mode that disables PAC key protections for that identity and potentially lowering barriers for in-memory execution abuse. Apple’s Endpoint Security framework was highlighted as a detection path, because defenders can monitor relevant process and memory-protection activity, including events tied to executable memory allocation and permission changes, to identify suspicious use of tclsh for shellcode staging and execution.

Get the actors, campaigns, and ATT&CK mapping behind it.
1 event from the most recent confirmed update back to the earliest known activity.
A blog post described how Apple's built-in Tcl interpreter on macOS Tahoe can be abused as a living-off-the-land binary to allocate executable memory, fetch payloads over HTTPS, and execute shellcode in memory using the preinstalled Ffidl library. The post also highlighted relevant detection opportunities via macOS Endpoint Security API mmap and mprotect events and noted tclsh's hardening exceptions and entitlements.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.