Categories: MacNews

Silver Sparrow Malware Threat Affects M1, Intel Macs

Mac owners are lucky. They don’t have to worry about malware as much as PC owners do. A new Mac malware threat named “Silver Sparrow” affects both Intel and Apple Silicon M1 Macs. We’ll talk about the malware, it’s potential, and how to find and remove it.

The Threat of Silver Sparrow

The true goal of this malware is unknown. Security company Red Canary published a detailed article describing how the malware was first detected. It takes advantage of JavaScript and macOS plists to perform its tasks.

Silver Sparrow’s precursors first appeared on August 18, 2020. The first detection by Red Canary was on January 26, 2021. There are now two varieties of this malware in the wild – one that affects only Intel Macs, and the other that can infect M1 Macs as well.

What could it potentially do? The malware checks a download URL on a regular basis, so it can deliver ransomware or annoying adware if it found a malevolent “payload” at the download site.

How Widespread Is This Malware?

Red Canary says that

“According to data provided by Malwarebytes, Silver Sparrow had infected 29,139 macOS endpoints across 153 countries as of February 17, including high volumes of detection in the United States, the United Kingdom, Canada, France, and Germany.”

Is It a Serious Threat?

From the Red Canary article:

Though we haven’t observed Silver Sparrow delivering additional malicious payloads yet, its forward-looking M1 chip compatibility, global reach, relatively high infection rate, and operational maturity suggest Silver Sparrow is a reasonably serious threat, uniquely positioned to deliver a potentially impactful payload at a moment’s notice. Given these causes for concern, in the spirit of transparency, we wanted to share everything we know with the broader infosec industry sooner rather than later.

Tony Lambert, Red Canary

Can Silver Sparrow Infect Your Mac?

Silver Sparrow and similar malware is considered a serious threat, but it’s not expected to spread much further. Apple suspended the developer certificates used to sign the package files that start the infection. If you use the Mac’s default security settings, the malware can’t be installed. That’s a relief!

What About Antivirus / Anti-Malware Software?

Any standard virus checker on your Mac — like the free versions of Malwarebytes or ClamXAV — finds and destroys Silver Sparrow during a standard scan. Make sure the definition files for the virus checker are up to date.

Manually Checking For Silver Sparrow and Deleting It

A Lifehacker post about Silver Sparrow describes four files whose existence suggests your Mac might be infected with the malware:

  • ~/Library/._insu
    (empty file used to signal the malware to delete itself)
  • /tmp/agent.sh
    (shell script executed for installation callback)
  • /tmp/version.json
    (file downloaded from from S3 to determine execution flow)
  • /tmp/version.plist
    (version.json converted into a property list)

A commenter on Ars Technica with the pseudonym “effgee” provided a detailed set of instructions on how to look for these files and clean up an infected Mac. We won’t repeat these here due to their length, but to perform a manual check and cleansing if you’re comfortable with the Terminal app, here’s a link.


To summarize, Silver Sparrow has been grounded by Apple and antivirus app publishers, but it did spread quickly. While the malware didn’t deliver a hazardous payload to any of the infected Macs, it has the potential to do so if not cleaned off of those Macs.

Steve Sande

Steve is the founder and former publisher of Apple World Today and has authored a number of books about Apple products. He's an avid photographer, an FAA-licensed drone pilot, and a really bad guitarist. Steve and his wife Barb love to travel everywhere!

Recent Posts

Growth in Mac sales driven by strength of the new MacBook Air with M3 processor

During a call with analysts regarding Apple’s latest finances, Apple Chief Financial Officer Luca Maestri…

7 hours ago

Apple CEO, CFO praise the Vision Pro’s reception in the enterprise market (but don’t mention sales figures)

Apple CEO Tim Cook and CFO Luca Maestri praise the Vision Pro’s reception in the…

7 hours ago

Apple quarterly revenue down 4% year-over-year, but Services and Mac revenues are up

Apple quarterly revenue is down 4% year-over-year, but Services and Mac revenues are up.

8 hours ago

Apple continues to look into ways to make the Vision Pro more comfortable

Apple continues to look into ways to make the Vision Pro more comfortable.

10 hours ago

Apple patent filing for ‘hinges for folding devices’ hints at an ‘iPhone Fold’

Apple has filed for another patent that hints at a foldable iPhone (of which I’m…

10 hours ago

Apple looks into an ‘Underwater User Interface’ for the iPhone

Apple has been granted a patent (number US 11875021 B2) for an “Underwater User Interface”…

10 hours ago