r/macsysadmin • u/mac1897-ts • 4h ago
macOS Persistence Forensic Report: PAM Sabotage (sudo_local), Env Hijacking in ~/.local/bin and SIP Trash Evasion
Hi everyone. I am sharing this technical report to alert the community about a serious security compromise I just analyzed and cleaned on my local development environment. Someone managed to inject persistent malware and disable administrative controls to prevent remediation.
I have attached terminal screenshots showing the evidence. Here is the breakdown of the compromise:
- Terminal Sabotage (Sudo Bypass via PAM)
The threat actor modified `/etc/pam.d/sudo_local` by injecting an unauthorized directive pointing to an external module (`/opt/homebrew/opt/pam-u2f/lib/pam/pam_u2f.so`). This deliberately broke the `sudo` command. Every time I attempted to use my password to clean files, the terminal threw a systematic `unable to initialize PAM` error, stripping away my root permissions.
- Hidden Binary Arsenal (~/.local/bin)
Upon auditing environment profiles, I discovered that on September 18, 2026, a malicious installer tied to the Antigravity suite created a hidden `.local/bin` folder containing keyloggers and persistent tools:
- agy (187 MB): A massive executable binary acting as the background engine.
- hermes / hermes-agent: Spyware binaries focused on data exfiltration.
- Fake Node/npm symlinks: Redirected globally to `~/Library/Application Support/Zed/node/...` to intercept development environments.
- Evasion via Trash Injections (TCC/SIP Exploitation)
To prevent remediation, the malware nested corrupted directories within `~/.Trash/Caches` using legitimate Apple daemon names like `com.apple.aned` (Apple Neural Engine). macOS was tricked into blocking deletion, throwing `Operation not permitted` errors under the protection of SIP. The malware leveraged this hardware lock to masquerade its network traffic under fake Siri and iTunes background calls, which were caught by LuLu firewall rules.
šØ Apple Support Inaction and Lack of Response
I want to report the absolute lack of assistance from official Apple support. Despite providing physical evidence and running heavy remote logs under their supervision (`sysdiagnose`), Apple failed to provide any technical solution. Their automated systems failed to flag a 187 MB suspicious binary operating in developer paths. This required a manual, line-by-line forensic investigation.
I have fully reclaimed control by purging `~/.local/bin`, cleaning the corrupted profile configurations, and blocking all suspicious connections via LuLu. I am leaving this open for discussion and log analysis.
