Become a MacRumors Supporter for $50/year with no ads, ability to filter front page stories, and private forums.

andymcc

macrumors newbie
Original poster
Jul 22, 2025
2
0
GB
Ex. IT admin here, returned to MacOS a year or so ago after ~2 decades on other platforms. So broadly experienced, but TBH fairly naive when it comes to more complex MacOS issues, so looking for some wise advice.

System is a MBP M4, running current MacOS.

A few months ago I installed Whisky app (via Github IIRC) in order to run 'MS Visio' as I needed to open some .vsd files. That sort of worked OK, and I did what I needed, then forgot about the 'Whisky' install.

This morning I needed to open an old .vsd file again, so fired up 'Whisky'. I got some odd warnings about Whisky wanting access to stange places it has no need to, iCloud drive and so on.

There was an a noticable delay before the Viso windows appeared, then all hell broke loose with multiple script windows popping up briefly, it was obviously highly dodgy was the executable path names had some weird stuff like 'windows 128-bit', and some German-looking language.

I quickly shut the Macbook lid to stop any further activity. But, what to next ?

A quick search didn't reveal very much useful guidance on how to deal with a compromised MacOS instance, how to alert the community and so on.

Ideally I'd like to boot the Mac off a clean OS instance, in order to try and see what has happened, copy off my 'docs' from my home directory, before blowing the OS away and restoring the whole machine from my last backup.
 
A few months ago I installed Whisky app (via Github IIRC)
If it is a virus, either you installed from a bad source (malicious github repo) or the developer put in some sort of timebomb that only activated now. I'd be curious to see the code signature (Apparency is a very good GUI for this), if it's the same as the one in the official repo, and if it is if the .app is identical to a fresh copy.
I got some odd warnings about Whisky wanting access to stange places it has no need to, iCloud drive and so on.
I can't say I'd be too surprised by this, I only used Whisky once and didn't get any of those pop-ups, but I do use wine and I know it by default links to folders in your home folder. Of course this also means that any exe run within wine/whisky will have access to pretty much everything in your home folder.
then all hell broke loose with multiple script windows popping up briefly, it was obviously highly dodgy was the executable path names had some weird stuff like 'windows 128-bit',
Personally I think it's far more likely that the virus is windows-based. Then again it could be the wine process doing housekeeping, your description isn't really detailed enough to say.
A quick search didn't reveal very much useful guidance on how to deal with a compromised MacOS instance, how to alert the community and so on.
I would zip up the Whisky.app and upload that to virustotal, in addition to the exe/dll files (or msi, if you still have it) of whatever software you installed. If it's already a known piece of malware, it will tell you. Otherwise, try contacting a security researcher, I know objective-see has researched this kind of stuff in the past.
 
Thanks folks ! I reset all my main passwords just in case, and did bit more reading up. Then I switched off the wifi and opened it up and hit the power key to try and shut it down, there were a bunch of Windows dialogs open for a second or so before it shut down.

So I think what I was seeing was in Win32 land, so the compromise was likely the old version of Visio I used :) Strangely its fine on my Win 10 PC (now retired). I think it unlikely MacOS was targeted at all.

Sorry to waste your time.. however for me it was a salutary lesson, if I want to run old Windows apps (and I may do) under Wine or whatever, I need to make sure they're properly denied internet access, which they may not be, by default.
 
Register on MacRumors! This sidebar will go away, and you'll see fewer ads.