The second known piece of malware that has been compiled to run natively on M1 Macs has been discovered by security firm Red Canary.
Given the name “Silver Sparrow,” the malicious package is said to leverage the macOS Installer JavaScript API to execute suspicious commands. After observing the malware for over a week, however, neither Red Canary nor its research partners observed a final payload, so the exact threat that the malware poses remains a mystery.
Nevertheless, Red Canary said the malware could be “a reasonably serious threat”:
Though we haven’t observed Silver Sparrow delivering additional malicious payloads yet, its forward-looking M1 chip compatibility, global reach, relatively high infection rate, and operational maturity suggest Silver Sparrow is a reasonably serious threat, uniquely positioned to deliver a potentially impactful payload at a moment’s notice.
Read more at MacRumors.com
