A new, sophisticated campaign is targeting users via a deceptive PDF, with the aim of infecting them with Mac malware called JSCoreRunner.

The malware represents a significant evolution in threats to macOS, showing how cybercriminals are adapting their techniques to bypass Apple's security measures, while maintaining zero detection rates on major security platforms.
JSCoreRunner malware: How does infection occur?
The threat operates via fileripple[.]com, a fake website that pretends to be a legitimate PDF conversion service. Users who visit the website are prompted to download what appears to be a useful tool called 'FileRipple.pkg'. This creates the illusion of a genuine PDF tool and displays a fake webview interface.
See also: MixShell malware distributed via Contact Forms
The malware performs its malicious activities silently, while users believe they are interacting with a legitimate application. 9to5Mac analysts identified this campaign as particularly concerning due to its zero-day status upon discovery.
The malware managed to evade all security vendors on VirusTotal, highlighting the advanced nature of this threat and the challenges faced by traditional detection methods.

The main goal of the JSCoreRunner malware is browser hijacking , specifically targeting Google Chrome installations on infected systems. JSCoreRunner systematically traverses the ~/Library/Application Support/Google/Chrome/ directory to locate both default and additional user profiles. It then manipulates search engine configurations via TemplateURL object modifications.
Infection in two stages
The JSCoreRunner campaign uses a carefully orchestrated two-stage deployment strategy designed to bypass macOS security checks . The initial stage involves a signed package that is intentionally crafted to appear legitimate, although Apple has since revoked the developer's signature. This revocation causes macOS Gatekeeper to block the first-stage package , creating a false sense of security for users who may assume the threat has been neutralized.
See also: New Android malware mimics Russian FSB antivirus
However, the second stage, 'Safari14.1.2MojaveAuto.pkg', operates as an unsigned payload downloaded directly from the same compromised domain. This unsigned nature allows it to bypass Gatekeeper's default blocking mechanisms, as macOS typically focuses on signature validation on initially downloaded packages rather than on subsequent downloads.
After successful installation, the malware establishes persistence by modifying Chrome's search engine settings and redirecting users to fake search engines while hiding error logs and session restoration prompts.
macOS users are facing a new threat that proves that cybercriminals are not shying away from finding increasingly creative ways to spread malware. JSCoreRunner hides behind a deceptive website that mimics a PDF conversion service, tricking unsuspecting visitors into downloading infected installation packages.
See also: QuirkyLoader helps distribute infostealer malware

This campaign stands out not only because of its sophistication, but also because it managed to completely evade detection systems on VirusTotal, leaving even experienced researchers talking about an extremely worrying zero-day scenario. Unlike more “traditional” attacks spread through phishing emails or cracked applications, here the perpetrators invested in a complete fake service, which enhances the sense of legitimacy.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
This case highlights a critical issue: the perception that Apple systems are inherently more secure can lead to complacency. The techniques used by JSCoreRunner show that attackers have a deep understanding of how the macOS ecosystem works and are developing tactics specifically designed to bypass built-in defenses.
The advice from experts is clear: users should only download software from the official Apple App Store or from trusted developers, and using up-to-date third-party security solutions is more necessary than ever. This new campaign shows that the war between malware developers and defenders continues, with attackers constantly finding new ways to stay one step ahead.
