indicatorfilename
/Library/Caches/com.apple.act.mond
- First seen
- 2026-05-13
- Last seen
- 2026-05-13
- Sightings
- 2
Posts referencing this indicator
- Supply Chain Attack on Axios Pulls Malicious Dependency from npm
macOS payload dropped by AppleScript, mimicking a legitimate Apple daemon.
- Axios NPM Package Compromised: Supply Chain Attack Hits JavaScript HTTP Client with 100M+ Weekly Downloads
macOS payload path mimicking an Apple system cache entry/daemon