Many people have always believed that Macs are very safe, with almost no viruses or malware. This is no longer the case. Recently, foreign security researchers discovered that seven software programs in the Mac App Store contained malicious code. Although they have been officially deleted, several of them are quite popular. For example, PDF Reader ranks first in the education rankings in the United States. There should be many users in Taiwan downloading and installing them. Check Mac quickly.

7 malware found in Mac App Store
Recently, foreign security researcher Privacy 1st (Alex Kleber) published a report on Medium that he found malware in the Mac App Store. He analyzed seven different Apple developer accounts and found that they were all from the same Chinese developer and were not independent:
- PDF Reader for Adobe PDF Files – From Sunnet Technology Inc
- Word Writer Pro – From Netozo Limited
- Screen Recorder – From Safeharbor Technology L Ltd
- Webcam Expert – from Wildfire Technology Inc
- Streaming Browser Video Player – From Boulevard Technology Ltd
- PDF Editor for Adobe Files – From Polarnet Limited
- PDF Reader – From Xu Lu

It can be noted that three of these seven are PDF tools. Privacy 1st also mentioned that all three are on the list, especially Adobe PDF Files, which won the first place in the education category of the US Mac App Store, which shows that many people have downloaded it. Although it is not ranked in Taiwan, there are not many PDF apps for Mac, so someone must have downloaded and installed it.

As for what kind of malicious behavior they will perform? According to the description, the most common method is to hide malware in commands received from the server. To put it simply, the app must pass the initial security check of the App Store before enabling the malware, or even remotely modify the UI, so that the software screen seen by the Apple review team is different from the final version seen by the user, and thus it is not discovered.
In addition, these apps also use popular services such as Cloudflare and GoDaddy to hide their hosting service providers and purchase some fake five-star reviews to improve their rankings:

As Privacy 1st revealed this report, Apple has also removed these Apps from the Mac App Store, but installed users still need to delete them themselves.
Although there does not seem to be any disaster at present, and it does not seem that Mac data or user information has been stolen, it is possible that Privacy 1st discovered it early, so that these seven Apps were discovered before taking action, which led to a larger security incident. In any case, if you do have it installed, it is recommended to scan it with anti-virus software after removing it, which will be safer.
Source: KOCPC Chinese