40% off with code HYPERLAUNCH

Claim offer
HyperMonitor
SecurityGuide 04 of 04

How to check launch agents for malware on a Mac

If you’ve found a launch agent you don’t recognise, you don’t have to guess. These checks show what it runs, who signed it and when it appeared, and how to remove it without breaking anything.

4 min read6 commands

Question 01

Why does Mac malware use launch agents?

Malware wants to survive a restart, and a launch agent is one of the simplest ways to do that on a Mac. A plist in a LaunchAgents folder with RunAtLoad set starts its program at every login, and KeepAlive brings the program back whenever it is quit. Your own ~/Library/LaunchAgents folder is especially attractive because any app you run can write to it without asking for an administrator password. That is why adware, browser hijackers and fake updaters so often leave a plist there, sometimes with a name that looks like it belongs to Apple, Google or another well-known company. Launch daemons in /Library/LaunchDaemons are more powerful, because they run as root, but they need an administrator password to install, so they usually appear after an installer asked for one. Checking these folders is therefore one of the first steps when a Mac starts behaving oddly.

Question 02

What are the warning signs of a malicious launch agent?

No single sign proves a launch agent is malicious, but several together should make you suspicious. Look for a label that imitates Apple, such as com.apple.something, in a folder outside /System, since Apple’s own jobs live under /System/Library. Random-looking names, or a label that doesn’t match any app you installed, are another signal. Check the program path in the plist: executables in /tmp, /Users/Shared, Downloads or a hidden folder inside ~/Library/Application Support are unusual for legitimate software. Be wary of ProgramArguments that run bash, sh, python3 or osascript with a script you can’t find an origin for, or that download something with curl. A plist created recently, around the time a problem started, is worth a closer look. So is an unsigned program, or one whose signature doesn’t match the company the label claims. Combine these clues before you decide anything.

Question 03

How do I check who signed a launch agent’s program?

Find the executable path in the plist’s Program or ProgramArguments, then run codesign -dv --verbose=4 with that path. The Authority lines show the signing chain: “Developer ID Application” followed by a name and team ID means a registered developer signed it, and Apple’s own software says “Software Signing”. “code object is not signed at all” means nobody vouches for it. codesign --verify --verbose followed by the path checks that the file hasn’t been modified since it was signed. spctl --assess --type execute -vv with the path asks Gatekeeper whether it would allow the program, and for apps, reports whether it was notarized by Apple. A valid signature doesn’t make software safe, and some genuine developer tools are unsigned, but a signature tells you who to hold responsible. To compare with known malware, shasum -a 256 gives a file hash you can search for on a reputable malware database.

Terminal — zsh
# Who signed it?codesign -dv --verbose=4 /path/to/program# Has it been modified since signing?codesign --verify --verbose /path/to/program# Would Gatekeeper allow it?spctl --assess --type execute -vv /path/to/program# File hashshasum -a 256 /path/to/program

Question 04

How do I safely remove a suspicious launch agent?

Write down the job’s label, its plist path and its program path first, so you can undo the change if it turns out to be something you need. Then unload the job so launchd stops restarting it: launchctl bootout gui/$(id -u) followed by the plist path for your own agents, or sudo launchctl bootout system and the path for a daemon in /Library/LaunchDaemons. Move the plist to the Trash rather than deleting it outright, and do the same with the program it pointed to once you’re sure nothing else uses it. Log out and back in, or restart, and check that the plist hasn’t come back. If it reappears, another component is re-creating it, often an app in /Applications or a second job in another LaunchAgents folder, so look for those next. Keep a recent backup before you start, and if you suspect a real infection rather than adware, get professional help.

Terminal — zsh
# Unload one of your agentslaunchctl bootout gui/$(id -u) ~/Library/LaunchAgents/com.example.agent.plist# Unload a system daemonsudo launchctl bootout system /Library/LaunchDaemons/com.example.daemon.plist