logo

MacOS Injection via Third Party Frameworks

ID: d19b437e-195f-5599-be40-9421aeedd115

STIX ID: report--d19b437e-195f-5599-be40-9421aeedd115

Feed Name: XPN Infosec Blog

Threat Score
70/100

Date Published: 2020-09-23

Date Updated: 2026-07-30

...
...

This report demonstrates practical techniques for bypassing macOS process-injection and privacy protections by leveraging third‑party runtimes: abusing .NET Core’s debug transport (named pipes) to read/write memory and achieve code injection (including a PoC that writes shellcode and loads an Apfell implant), and using ELECTRON_RUN_AS_NODE to run signed/hardened Electron apps as Node to spawn processes that inherit app privacy permissions; the post includes full PoC code, implementation details, and evidence showing these methods work against hardened binaries.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.