Security agency Jamf Threat Labs recently released a security report on macOS, pointing out that the malware problem in macOS is becoming increasingly serious. Jamf Threat Labs pointed out,In the past, many people believed that macOS was safer. In fact, the reason was that the user base of macOS was small and hackers were not interested in it. However, as the Mac market share continues to grow, the problem of malware has become more and more serious.

Historically, macOS's software distribution model has worked well, with apps outside the Mac App Store having to be cryptographically signed and certified, but Jamf noted that hackers are purchasing or stealing real developer ID certificates through underground channels.
Because these malware have Apple's "notarized certificate", they look exactly like legitimate software when installed, and Mac will not block them at all.
In addition, malicious code is often encapsulated in seemingly harmless Swift execution files. In Apple's static analysis, they perform almost no operations and perfectly avoid review.
Jamf criticized Apple's certification process for being too rigid. Hackers provide "clean" content when submitting for review, but once the program is running on the user's computer and connected to the network, it downloads and loads the real malicious code from the cloud.
This "pass the review first, then become poisonous" tactic makes Apple's security restrictions useless.The original intention of code signing is to ensure that software can be traced back to the real developer and to revoke the signature if abuse is discovered, but this does not guarantee that the software will never be harmless.
As the user base of macOS expands, so does hackers' interest in it. Apple users need to remain vigilant at all times and try to avoid downloading applications outside the Mac App Store to reduce security risks.