Skip to content
JKULDEV

Blog

Notes on what we build and what we find along the way. Mostly macOS internals, storage and security — written up the way we would want to read them.

Illustration for “A malware loader that hid its command server on a blockchain”

Latest

A malware loader that hid its command server on a blockchain

A launch agent found on a working Mac read its command-and-control address out of a smart contract on Polygon, then piped the reply straight into osascript. Storing the address on-chain makes it impossible to take down by seizing a domain.

8 min read
  • Reclaim
  • security
  • macos
  • malware
Read →