Don’t Listen to Anyone Who Tells You to Drag a Text File into Terminal

In macOS 15 Sequoia, Apple made it more difficult to bypass Gatekeeper to run apps that aren’t notarized. (Notarization is one of the ways Apple ensures that apps distributed outside the Mac App Store are unmodified and free from malware.) Cybercriminals have responded to this increase in security with a new social engineering attack. They provide the victim with a disk image, ostensibly to install some desired piece of software, instructing the user to drag a text file into Terminal. Doing so executes a malicious script that installs an “infostealer” designed to exfiltrate a wide variety of data from your Mac. The simple advice here is to treat any guidance to drop a file into Terminal with extreme suspicion—no legitimate software or developer will ever ask you to do that.

(Featured image based on an original by iStock.com/Farion_O)


Social Media: Thing #17 to never do: Follow instructions to drop a text file into Terminal. It’s a great way to install malware and let cybercriminals steal your passwords, financial information, and more.

Similar Posts

  • My daughter Autumn and her husband Ismael are coming to visit next week which should be fun. Then we pack up and head back to Vermont. Hopefully the weather will cooperate but it seems like warmer weather is in the forecast for the Green Mountains.

    Thank you so much for reading this issue of Kibbles & Bytes!

    Your Kibbles & Bytes Team,

    _Don, Emily, Hadley & Amy_

  • Your Kibbles & Bytes Team,

    _Don, Emily & Dean_

  • Who cares about QR Codes?

    By now you’ve probably seen one of those odd-looking white squares with a bunch of smaller square dots that make up a random pattern inside–that’s a QR code. QR stands for “Quick Response,” and a QR code is a form of barcode, just like on the packaging of nearly everything you buy.

    Usually QR codes are used to store Web links–URLs–so an ad can display just the QR code instead an unwieldy and hard-to-type web address. But QR codes aren’t just for ads. They’ve appeared on business cards, in magazines and books, on coins and bills, and even on tombstones–any place it would be nice to help someone load a Web link into a smartphone but where there isn’t enough room for a URL or in situations where viewers won’t remember the URL later. And the links? They can display anything that can appear on the Web: text, photos, videos, games, and more.

    Only one built-in iPhone app can scan QR codes–the Wallet app in iOS 9–but it can scan only QR codes that are associated with Wallet passes, things like airline boarding passes, concert tickets, and iTunes gift cards. For QR codes that encode any other sort of data, Wallet shows an error. It would be nice if Apple would add general QR scanning capabilities to Wallet or the Camera app, but until that happens, you’ll need another app.
    There are numerous QR code scanning apps in the App Store, but if you need a recommendation, give TapMedia’s QR Reader for iPhone a try. It’s free with ads (remove them with a $1.99 in-app purchase), scans both QR codes and traditional barcodes on most commercial products, and displays the associated information within the app. It can even help you create your own QR codes.

    To use a QR code scanner, launch the app, allow it to access the camera when it asks, and then point it at the QR code. Good apps will scan nearly instantly, but if not, move the camera so the QR code is centered between the guides. If even that doesn’t work, move forward or back so the camera can focus on the centered code.

    Once the code has been scanned, the app will usually bring up an in-app Web browser to display whatever was encoded. For certain kinds of data, like books or grocery items, the app may go right to Amazon or a price comparison site. Good apps will also keep a record of sites you’ve scanned, so you can go back to them later, even if you can no longer scan the QR code.

    So download a QR code scanning app and keep an eye out for QR codes. Once you start looking, you’ll find them everywhere–it’s a modern-day treasure hunt!

  • Lift Objects from Photos on the iPhone

    Have you ever wanted to extract an object from a photo for use in another context? Starting with iOS 16 on a relatively…