# OSX.Shlayer Malware Gains Apple Notarization

Published: 2020-08-30 · Severity: medium
Canonical: https://vorant.io/reports/507864f7-8a6b-569d-94e7-1ef997ef06b3/osx-shlayer-malware-gains-apple-notarization

> A fake Homebrew site (homebrew.sh) served OSX.Shlayer/Bundlore adware installers that Apple mistakenly notarized, letting them run as trusted software even on macOS Big Sur.

Researcher Patrick Wardle documents the first known case of malware bypassing Apple's code-notarization requirement, a security control introduced in macOS Catalina meant to ensure all distributed software is scanned by Apple before execution. A malicious site, homebrew.sh — a typosquat of the legitimate brew.sh — served fake Adobe Flash Player updates that led to installers ultimately identified as OSX.Shlayer, a highly prevalent macOS trojan that installs the Bundlore adware family. Unlike prior Shlayer campaigns which used unnotarized payloads blocked outright by macOS, these samples carried valid Apple notarization stamps, allowing them to execute without the usual warning/block dialog and lending them false legitimacy in the eyes of victims.

Analysis of the payloads showed a self-decrypting shell routine using openssl AES-256-CBC to extract and execute a hidden binary appended to an image file, consistent with known Shlayer techniques, alongside chmod and cleanup steps. Once notified, Apple revoked the abused Developer ID certificates on Aug 28, 2020, but the campaign persisted, re-signing and re-notarizing near-identical payloads under new developer identities within roughly 48 hours, demonstrating attacker agility in continuing to evade Apple's vetting pipeline.

The incident undercuts Apple's marketing claim that notarization gives users confidence software has been checked for malicious content, since known, actively distributed malware slipped through the review process at least twice. Given Shlayer's status as one of the most prevalent macOS malware families (per Kaspersky), and its role as an adware/PUP dropper, the notarization bypass represents a meaningful trust-model failure even though the payload itself is not a high-impact backdoor, primarily driving adware monetization rather than data theft or destructive impact.

## Mentioned in this report

- Malware: Bundlore, OSX.Shlayer

Source reporting: https://objective-see.org/blog/blog_0x4E.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/507864f7-8a6b-569d-94e7-1ef997ef06b3/osx-shlayer-malware-gains-apple-notarization.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
