XProtect 5357 reaches every macOS with five new malware rules (August 26, 2026)

Chapters
What is in XProtect 5357
This is a security data update, not a macOS release. The content is detection rules, and 5357 adds ten of them. Five are Yara rules: CROOKEDCRUSTACEAN.IMPLANT.A, MACOS.ODYSSEY.XOOB, MACOS.SHADYSHOELACE.RUOP, MACOS.SHADYSHOELACE.BUAR and MACOS.SHADYSHOELACE.DEPA. Five are OSAScript rules: MACOS.OSASCRIPT.TITEST, MACOS.OSASCRIPT.TIPAHA, MACOS.OSASCRIPT.TIKEGR, MACOS.OSASCRIPT.TISASH and MACOS.OSASCRIPT.TIINCO. Five new OSAScript rules in one update is consistent with payloads delivered through AppleScript.
Two existing rules were amended as well: the Yara rule for MACOS.BONZAIBONANZA.VACA and the OSAScript rule for MACOS.OSASCRIPT.SYPR. Distribution came in two steps the same day. It was first released for macOS Sequoia and later through iCloud, with the install label XProtectPlistConfigData_10_15-5357, and then for all versions of macOS through softwareupdate, which is the wider push that reaches older systems.
| Rule | Kind | Change in 5357 |
|---|---|---|
| CROOKEDCRUSTACEAN.IMPLANT.A | Yara | New |
| MACOS.ODYSSEY.XOOB | Yara | New |
| MACOS.SHADYSHOELACE.RUOP | Yara | New |
| MACOS.SHADYSHOELACE.BUAR | Yara | New |
| MACOS.SHADYSHOELACE.DEPA | Yara | New |
| MACOS.BONZAIBONANZA.VACA | Yara | Amended |
| MACOS.OSASCRIPT.TITEST | OSAScript | New |
| MACOS.OSASCRIPT.TIPAHA | OSAScript | New |
| MACOS.OSASCRIPT.TIKEGR | OSAScript | New |
| MACOS.OSASCRIPT.TISASH | OSAScript | New |
| MACOS.OSASCRIPT.TIINCO | OSAScript | New |
| MACOS.OSASCRIPT.SYPR | OSAScript | Amended |
TL;DR
Apple pushed XProtect 5357 to every supported version of macOS on August 26, 2026, including macOS Tahoe 26.6.2 and the macOS 27 Golden Gate betas, according to The Eclectic Light Company that day. It adds detection for five new malware families, among them an Odyssey stealer variant and three ShadyShoelace variants, and Apple published nothing about what it addresses. There is no user-visible symptom here: the problem is that delivery is silent, and on macOS 27 the documented way to check for a pending update still errors out.
- XProtect 5357 went first to macOS Sequoia and later via iCloud, then to all macOS versions through softwareupdate, under the install label XProtectPlistConfigData_10_15-5357.
- Five new Yara rules and five new OSAScript rules were added, plus one amended rule of each kind.
- The five OSAScript additions are consistent with AppleScript-delivered payloads.
- Apple 'doesn't release information about what security issues this update might address', so there is no advisory to read.
- Running sudo xprotect check still results in an error on macOS 27, although the update mechanism itself works there.
Apple publishes nothing about what it addresses
There is no advisory for this. Apple 'doesn't release information about what security issues this update might address', as the second of the two write-ups that day puts it, at The Eclectic Light Company on August 26, 2026. The rule names are the only public description of what changed.
So the honest position for a Mac owner is this: ten detection rules arrived, five of them for malware families you cannot look up in an Apple document, and you were never told whether anything on your machine matched them. That is the standing arrangement for XProtect data updates, not something new on this day.
Confirming it arrived is harder than it should be
The place to look is System Information, reached through About This Mac, where Installations under Software lists what has been delivered. To force the update rather than wait for it, sudo xprotect update in Terminal does the job, and SilentKnight is the alternative for people who would rather not use Terminal.
On macOS 27 there is a gap. Running sudo xprotect check still results in an error, although the update mechanism itself functions properly on Golden Gate and other versions. In practice that means you cannot confirm on macOS 27 whether an update is pending before you force one. The cost of the whole procedure is a Terminal window and an admin password, for a security update that is meant to arrive by itself.
What else was and was not shipping
Nothing about this changes your macOS version. The newest public Tahoe release is still 26.6.2, and its release note reads only 'This update provides security fixes for your Mac', on Apple's 'What's new in the updates for macOS Tahoe 26' page, Apple Support as published on August 17, 2026. That page stops at 26.6.2, so a person keeping up to date on this day is on 26.6.2 plus XProtect 5357.
It is worth naming the limit of a data update like this one. It changes what XProtect detects. It does not close a vulnerability in macOS, and it does not tell you whether the families it now detects were ever on your Mac.
What you can do today
1. Check what you have. Open About This Mac, then System Information, then Installations under Software, and look for XProtectPlistConfigData_10_15-5357 in the list.
2. If it is not there, run sudo xprotect update in Terminal, which pulls it rather than waiting for the background delivery.
3. On macOS 27, skip the check step. sudo xprotect check errors on that release, so go straight to the update command.
4. If you would rather not open Terminal at all, SilentKnight will force the same update without it.
5. Do not wait for an advisory to tell you whether this mattered. There is not going to be one for an XProtect update, so the version number in Installations is the only confirmation available.
If checking a rule version by hand on every Mac in the house is not work you want, the honest answer is to have something else do it. Get XLAnt.
Frequently asked questions
Do I need to do anything for XProtect 5357?
Usually not. It is delivered in the background to all supported macOS versions, and the only reason to act is to confirm it arrived or to pull it sooner. The check is System Information, then Installations under Software, looking for XProtectPlistConfigData_10_15-5357.
What malware does it detect?
The rule names are all that is public: an Odyssey stealer variant, three ShadyShoelace variants, one CrookedCrustacean implant and five new AppleScript rules. Apple does not publish what security issues an XProtect update addresses, so there is no further detail to give.