Skip to main content
  1. Home
  2. Computing
  3. Legacy Archives

Low-Threat Mac OS X Trojan Appears

Add as a preferred source on Google

A Trojan horse aimed at Apple’s Mac OS X operating system has appeared, purporting to be screenshots of the company’s forthcoming Mac OS X 10.5 “Leopard” operating system. Although the Trojan, dubbed “OSX/LeapA” by antivirus firms, can spread itself via the iChat instant messaging program and damage applications on a Mac OS X computer, unlike many Windows Trojans, it spreads by fooling users into launching it manually, rather than by leveraging security flaws in the operating system.

The Trojan was uploaded earlier this week to the MacRumors Forums site under the filename latestpics.tgz. Longtime Macintosh developer Andrew Welch of Ambrosia Software has posted a detailed analysis of the malware, which he initially dubbed “Oompa-Loompa.” When executed, the Trojan attempts to send itself to the user’s iChat contacts and damages applications on the user’s computer in attempts to spread itself. The trojan appears to attempt to spread itself through other applications as the user launches them, but, due to a bug, winds up damaging the applications, which then fail to launch.

Recommended Videos

The overall thread from OSX/LeapA is low. In order to be infected, users must:

  • acquire the Trojan, whether via download, email, iChat, or another means
  • manually decompress the file, and
  • manually open the decompressed file (which, for most users, will entail entering their administrator password)

The Trojan cannot spread between computers using a security loophole or other automatic mechanism: to be “infected,” a user must manually unarchive the file and deliberately open it.

Mac OS X users can easily protect themselves by simply not opening any archive they’re not expecting (especially via email or iChat, or if it’s called latestpics.tgz). Sophos and Symantec have already updated their virus definitions to detect OSX/LeapA, and are collecting information about the Trojan.

Geoff Duncan
Former Contributor
Geoff Duncan writes, programs, edits, plays music, and delights in making software misbehave. He's probably the only member…
The maker of ChatGPT wants to make open-source projects less of a security bargain
OpenAI launches Patch the Planet for open-source security, with over 30 open-source projects on board.
openai-chatgpt-os

OpenAI has launched Patch the Planet, a new initiative aimed at fixing one of the internet's quietest problems – the chronically underfunded security of open-source software.

Patch the Planet pairs OpenAI's most security-capable AI models with Trail of Bits, a security firm that has committed its entire research organization to the effort, alongside support from HackerOne and Calif.

Read more
I sifted through the Prime Day chaos to find the best Apple deals actually worth buying
Apple's about to hike prices. Prime Day 2026 is your last chance to save up to $150 on MacBooks, AirPods, and iPads.
Prime Day Deals on Apple Products

Apple is set to increase the prices for its upcoming iPhones and MacBooks, as the company can no longer offset the rising RAM and storage costs. That means, if you are looking to upgrade your aging device, you should buy the current-generation Apple products rather than wait for the new ones.

And since Amazon Prime Day is offering good discounts on the latest iPhones, iPads, MacBooks, and other Apple accessories, this is the perfect time to buy them. Here are my favorite Amazon Prime Day deals for Apple products. 

Read more
This sneaky photo trick gets AI chatbots to ignore their safety rules
Florida International University researchers built a method that nearly doubled the rate of harmful responses from a tested AI model using nothing but pixel-level edits in an image.
JaiLIP AI chatbot exploit image

A photo that looks completely ordinary to you could carry a hidden instruction to trick an AI chatbot into ignoring its safety rules, according to new research out of Florida International University. The study found that pixel-level alterations in an image that are invisible to the human eye can be enough to confuse the model reading the image and lead it to generate responses it would normally block.

Hacking what the AI sees

Read more