logo

MacOS Injection via Third-Party Frameworks

ID: e7b90360-149b-5253-a607-a54ae7876893

STIX ID: report--e7b90360-149b-5253-a607-a54ae7876893

Feed Name: TrustedSec blog

Threat Score
65/100

Date Published: 2025-03-19

Date Updated: 2026-05-01

...
...

This report details PoC techniques for macOS post-exploitation: leveraging .NET Core’s debug transport named pipes to perform remote process memory read/write and code injection into signed/hardened processes, and abusing Electron’s ELECTRON_RUN_AS_NODE environment variable to execute Node code under a signed app and inherit TCC/privacy permissions (demonstrated by injecting an Apfell implant). The author documents discovery, PoC code, and mitigation-relevant observations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.