Login Item Persistence
Registering an app as a macOS Login Item via SMAppService or the legacy shared-file-list API — a persistence surface separate from LaunchAgents, driven through System Settings rather than a launchd plist.
Login Items are a persistence surface distinct from LaunchAgents/LaunchDaemons:
apps registered to open automatically at login through
System Settings > General > Login Items, historically configured via the
Shared File List API or osascript's System Events Login Items object, and
on modern macOS via the SMAppService framework, which registers a helper
tool or agent alongside a main app bundle without writing a separate
LaunchAgent plist by hand. Because this mechanism is UI-driven rather than a
raw property list, it was historically less scrutinized by defenders whose
tooling only enumerated ~/Library/LaunchAgents and
/Library/LaunchAgents; anything on this surface never showed up there at
all.
How it works
The legacy route scripts the Shared File List directly:
tell application "System Events"
make login item at end with properties {path:"/Users/victim/Library/Application Support/.helper/agent.app", hidden:true}
end tellThe modern route, used by apps targeting current macOS, registers a
SMAppService login item or agent programmatically from within the app's own
code — the OS then manages starting it at login and tracks the registration in
its Background Task Management (BTM) database rather than a plist an analyst
can just cat.
Detection & analysis
Static analysis:
- A sample that calls into
ServiceManagement/SMAppServiceAPIs, or shells out toosascriptwith aSystem Events ... login itemscript, is registering itself for login persistence through this surface specifically — distinguish it from LaunchAgent-based persistence in your notes, since the remediation path differs. - Inspect an app bundle's
Info.plistforSMAuthorizedClients/SMPrivilegedExecutableskeys that name a helper tool intended to be registered this way.
Dynamic analysis:
sfltool dumpbtmenumerates the Background Task Management database on current macOS, listing every registered login item, agent, and daemon regardless of which API registered it — this is the authoritative modern view, since it also catches entries LaunchAgent-only tooling misses.System Settings > General > Login Items & Extensionsshows the same list to a human reviewer; compare it against a known-good baseline for the machine.
Detection rule hint:
Alert on new entries appearing in the BTM database (sfltool dumpbtm) or the
Shared File List login-items store whose target binary is unsigned, ad-hoc
signed, or resides outside /Applications, especially when the registering
process is not a package installer.