XProtect 5358 adds Dubrobber detection to every macOS, Tahoe 26.6.2 included (September 2, 2026)

Chapters
TL;DR
Apple pushed XProtect 5358 overnight to every version of macOS, covering macOS Tahoe 26.6.2, macOS Sequoia and the macOS 27 Golden Gate betas, reported by The Eclectic Light Company on September 2, 2026. It adds six new Yara rules, two of them for the Dubrobber family and four for ShadyShoelace, plus two new OSAScript rules, which is consistent with AppleScript-delivered payloads. Nothing about it is visible to the user: the update arrives silently, Apple publishes no information about what an XProtect update addresses, and on macOS 27 the documented sudo xprotect check command still errors, so on that release you cannot confirm whether an update is pending before forcing one.
- XProtect 5358 shipped overnight into September 2, 2026 for all versions of macOS, superseding 5357 from August 26, 2026.
- New Yara rules: MACOS.DUBROBBER.SAINDY, MACOS.DUBROBBER.CHREIM and four ShadyShoelace variants.
- New OSAScript rules: MACOS.ANGRYORB.JXPL and MACOS.OSASCRIPT.DUEXKE.
- Dubrobber coverage is what is new against 5357, which carried none.
- Confirm delivery in System Information, under Installations in the Software section; force it with
sudo xprotect updateor SilentKnight.
What shipped on September 2
The report is exact about the scope: "Apple has overnight released its regular weekly update to XProtect, bringing it to version 5358, for all versions of macOS." There is no user-facing release note, because Apple does not publish one for XProtect. The only way to know what changed is to read the rules that were added.
Six Yara rules and two OSAScript rules are new. The OSAScript rules matter more than their names suggest: OSAScript detection targets AppleScript, so a batch of new OSAScript rules points at payloads being delivered as scripts rather than as compiled binaries.
This is a mitigation delivered out of band, not a fix for a macOS defect. There is no symptom to look for and no reboot involved. The practical question for a person at the keyboard is only whether their Mac actually received it.
| Item | Value |
|---|---|
| XProtect version | 5358 |
| Previous version | 5357, released August 26, 2026 |
| Coverage | All versions of macOS |
| New Yara rules | MACOS.DUBROBBER.SAINDY, MACOS.DUBROBBER.CHREIM, MACOS.SHADYSHOELACE.OSLOSTA, MACOS.SHADYSHOELACE.OSLODL, MACOS.SHADYSHOELACE.LODLSYDEAR, MACOS.SHADYSHOELACE.LODLSYDEX8 |
| New OSAScript rules | MACOS.ANGRYORB.JXPL, MACOS.OSASCRIPT.DUEXKE |
What is new against XProtect 5357
A week earlier Apple shipped XProtect 5357 to all versions of macOS, which I covered in the August 26 post. That release added rules for CROOKEDCRUSTACEAN.IMPLANT.A, MACOS.ODYSSEY.XOOB and three ShadyShoelace variants, and it carried no Dubrobber coverage at all.
So the materially new element in 5358 is Dubrobber, plus four further ShadyShoelace variants on top of the three from the week before. ShadyShoelace appearing in two consecutive weekly updates, with seven variants between them, is the pattern worth noticing here.
The cadence itself is useful information. XProtect updates arrive roughly weekly, so a Mac that has not seen one in several weeks is worth checking rather than assuming.
Why Dubrobber matters
Dubrobber is also tracked as XCSSET. A variant of that family was analysed by Palo Alto Networks Unit 42 and reported by BleepingComputer on August 4, 2026, a month before this XProtect release.
Its behaviour is the reason a detection update for it is worth a paragraph. The malware "aggressively attempts to disable macOS security such as XProtect, MRT, TCC, and Rapid Security Response, terminates Apple's CloudTelemetryService, and prevents XProtect signature updates". A payload that blocks XProtect signature updates makes the very mechanism that detects it unreliable, which is an argument for confirming your own XProtect version rather than assuming it.
The delivery route is narrow but effective: it spreads "by compromising vulnerable Git repositories and injecting a downloader script into benign files within Xcode projects", infecting developers when they build the project. BleepingComputer reports that the family targets thousands of macOS users.
The check that still does not work on macOS 27
The documented sequence for a manual update is sudo xprotect check followed by sudo xprotect update. On macOS 27 the first half of that still errors, as it did on August 26, 2026, while the update mechanism itself functions normally on Golden Gate and on other versions.
The cost of that gap is small but real. On macOS 27 you cannot find out whether an update is pending before you force one, so the only honest advice on that release is to skip the check and run the update. Manual checking is covered for Sequoia, Tahoe and Golden Gate systems, and either path needs Terminal and an administrator password.
What you can do today
1. Confirm the Mac received it. Open System Information via About This Mac, select Installations under Software, and look for the XProtect entry. The version you want is 5358.
2. If it is not there, force it. Run sudo xprotect update in Terminal, or use SilentKnight. You need an administrator password, and that is the entire cost.
3. On macOS 27 Golden Gate, do not bother with sudo xprotect check first. It still errors, so run the update directly and then verify in System Information.
4. If you build software in Xcode, treat third-party project files as untrusted input. Dubrobber, tracked as XCSSET, arrives by injecting a downloader script into ordinary files inside Xcode projects from compromised Git repositories, and it infects you at build time, not at download time.
5. Do not wait for an Apple advisory explaining what this fixed. Apple does not release information about what security issues an XProtect update addresses, so the rule names are the only detail you will get.
Frequently asked questions
Do I need to restart after an XProtect update?
Nothing published about XProtect 5358 mentions one. It is a background security data update delivered silently, and the only step reported is confirming the version in System Information or forcing it with sudo xprotect update.
Why does Apple not say what XProtect 5358 fixes?
Because it does not publish that. The August 26, 2026 report of the previous release states plainly that Apple "doesn't release information about what security issues this update might address", so the added rule names are the only description available.