{"id":84208,"date":"2018-11-14T11:32:03","date_gmt":"2018-11-14T19:32:03","guid":{"rendered":"https:\/\/www.intego.com\/mac-security-blog\/?p=84208"},"modified":"2026-08-08T05:11:44","modified_gmt":"2026-08-08T12:11:44","slug":"ad-injecting-mac-malware-rediscovered","status":"publish","type":"post","link":"https:\/\/www.intego.com\/mac-security-blog\/ad-injecting-mac-malware-rediscovered\/","title":{"rendered":"Ad-injecting Mac malware rediscovered: SearchPageInjector\/SearchAwesome"},"content":{"rendered":"<p>Most people assume that there&#8217;s little, if any, Mac malware out there in the wild. Unfortunately, that notion is merely wishful thinking.<\/p>\n<p>Malware analysts\u2014even those focused on Mac malware\u2014process so many malware samples that not every new piece of malware necessarily gets its own dedicated article or press release.<\/p>\n<p>Such was the case with <strong>OSX\/SearchPageInjector<\/strong>, Mac malware that Intego has been detecting since January 2018. OSX\/SearchPageInjector recently came back on our radar after Thomas Reed wrote up a <a href=\"https:\/\/blog.malwarebytes.com\/threat-analysis\/2018\/10\/mac-malware-intercepts-encrypted-web-traffic-for-ad-injection\/\" target=\"_blank\" rel=\"noopener\">piece<\/a> about it under the name OSX.SearchAwesome.<\/p>\n<p>Since it has been in the news recently, let&#8217;s take a look at what this malware does and how to avoid it.<\/p>\n<h3>What Is OSX\/SearchPageInjector?<\/h3>\n<p><strong>OSX\/SearchPageInjector<\/strong> is Mac malware designed to inject remotely hosted JavaScript code into every Web page the victim visits.<\/p>\n<p>The JavaScript code has been observed to inject advertisements, but it could also potentially be used for cryptojacking\u2014i.e. hijacking the Mac&#8217;s processing power to mine cryptocurrency on behalf of the attacker; see our <a href=\"http:\/\/podcast.intego.com\/33\" target=\"_blank\" rel=\"noopener\">audio podcast<\/a> and our\u00a0<a href=\"https:\/\/youtu.be\/3DW_MaoCmGU\" target=\"_blank\" rel=\"noopener\">YouTube video<\/a> on cryptojacking\u2014or more sinister purposes such as stealing usernames and passwords.<\/p>\n<p>OSX\/SearchPageInjector makes use of open-source man-in-the-middle proxy software to inject the attacker&#8217;s JavaScript code into all Web sites\u2014even those delivered over HTTPS, the more secure HTTP alternative that&#8217;s used by most popular Web sites.<\/p>\n<h3>How Do Macs Get Infected With OSX\/SearchPageInjector?<\/h3>\n<p>This malware comes as a second-stage infection after a user downloads a supposedly &#8220;cracked&#8221; version of an app from a torrent.<\/p>\n<p style=\"text-align: center;\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-65881\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2017\/04\/Torrents-Scan-Results.png\" alt=\"\" width=\"600\" height=\"328\" srcset=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2017\/04\/Torrents-Scan-Results.png 600w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2017\/04\/Torrents-Scan-Results-150x82.png 150w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2017\/04\/Torrents-Scan-Results-300x164.png 300w\" sizes=\"auto, (max-width: 600px) 100vw, 600px\" \/>Apps downloaded from <a href=\"https:\/\/www.intego.com\/mac-security-blog\/why-bittorrent-sites-are-a-malware-cesspool\/\" target=\"_blank\" rel=\"noopener\">torrents<\/a>\u00a0often contain malware.<\/p>\n<p>Thus, to avoid this particular infection, users simply need to avoid the temptation to download illegal copies of software.<\/p>\n<h3>How Can I Clean an Infected Mac?<\/h3>\n<p><a href=\"https:\/\/www.intego.com\/antivirus-mac-internet-security\" target=\"_blank\" rel=\"noopener\">Intego VirusBarrier<\/a> has been detecting and eradicating OSX\/SearchPageInjector since January 2018.<\/p>\n<p>If the malware has been removed from your computer and you know you don&#8217;t use the open-source\u00a0software\u00a0<a href=\"https:\/\/mitmproxy.org\/\">mitmproxy<\/a>, then you&#8217;ll also want to open the Keychain Access app (found in the \/Applications\/Utilities folder) and search for and delete the root certificate authority named mitmproxy.<\/p>\n<p style=\"text-align: center;\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-84223\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2018\/11\/mitmproxy-Root-Certificate-Authority-CA-in-Keychain-Access-app-2.png\" alt=\"\" width=\"877\" height=\"555\" srcset=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2018\/11\/mitmproxy-Root-Certificate-Authority-CA-in-Keychain-Access-app-2.png 877w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2018\/11\/mitmproxy-Root-Certificate-Authority-CA-in-Keychain-Access-app-2-150x95.png 150w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2018\/11\/mitmproxy-Root-Certificate-Authority-CA-in-Keychain-Access-app-2-300x190.png 300w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2018\/11\/mitmproxy-Root-Certificate-Authority-CA-in-Keychain-Access-app-2-768x486.png 768w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2018\/11\/mitmproxy-Root-Certificate-Authority-CA-in-Keychain-Access-app-2-657x416.png 657w\" sizes=\"auto, (max-width: 877px) 100vw, 877px\" \/>If you didn&#8217;t install mitmproxy, delete its root CA in Keychain Access. Screenshot: <a href=\"https:\/\/blog.malwarebytes.com\/threat-analysis\/2018\/10\/mac-malware-intercepts-encrypted-web-traffic-for-ad-injection\/\" target=\"_blank\" rel=\"noopener\">Reed<\/a><\/p>\n<h3>Where Can I Learn More?<\/h3>\n<p>We briefly discussed OSX\/SearchPageInjector on the <a href=\"http:\/\/podcast.intego.com\/55\" target=\"_blank\" rel=\"noopener\">November 2 edition<\/a> of the Intego Mac Podcast; be sure to <a href=\"https:\/\/itunes.apple.com\/us\/podcast\/intego-mac-podcast\/id1293834627\" target=\"_blank\" rel=\"noopener\">subscribe<\/a> to make sure you don&#8217;t miss future episodes!<\/p>\n<p>For\u00a0additional technical details about OSX\/SearchPageInjector, you can\u00a0refer to\u00a0<a href=\"https:\/\/blog.malwarebytes.com\/threat-analysis\/2018\/10\/mac-malware-intercepts-encrypted-web-traffic-for-ad-injection\/\" target=\"_blank\" rel=\"noopener\">Reed&#8217;s write-up<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Most people assume that there&#8217;s little, if any, Mac malware out there in the wild. Unfortunately, that notion is merely wishful thinking. Malware analysts\u2014even those focused on Mac malware\u2014process so many malware samples that not every new piece of malware necessarily gets its own dedicated article or press release. Such was the case with OSX\/SearchPageInjector, [&hellip;]<\/p>\n","protected":false},"author":14,"featured_media":84232,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[190],"tags":[86,4399],"class_list":["post-84208","post","type-post","status-publish","format-standard","has-post-thumbnail","category-malware","tag-mac-malware","tag-osxsearchpageinjector"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO Pro 5.0.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"Most people assume that there&#039;s little, if any, Mac malware out there in the wild. Unfortunately, that notion is merely wishful thinking. Malware analysts\u2014even those focused on Mac malware\u2014process so many malware samples that not every new piece of malware necessarily gets its own dedicated article or press release. Such was the case with OSX\/SearchPageInjector,\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Joshua Long\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/www.intego.com\/mac-security-blog\/ad-injecting-mac-malware-rediscovered\/\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO Pro (AIOSEO) 5.0.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"The Mac Security Blog - Keep Macs safe from the dangers of the Internet\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"Ad-injecting Mac malware rediscovered: SearchPageInjector\/SearchAwesome\" \/>\n\t\t<meta property=\"og:description\" content=\"Most people assume that there&#039;s little, if any, Mac malware out there in the wild. Unfortunately, that notion is merely wishful thinking. Malware analysts\u2014even those focused on Mac malware\u2014process so many malware samples that not every new piece of malware necessarily gets its own dedicated article or press release. Such was the case with OSX\/SearchPageInjector,\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/www.intego.com\/mac-security-blog\/ad-injecting-mac-malware-rediscovered\/\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2018-11-14T19:32:03+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2026-08-08T12:11:44+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/integogroup\/\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n\t\t<meta name=\"twitter:site\" content=\"@IntegoSecurity\" \/>\n\t\t<meta name=\"twitter:title\" content=\"Ad-injecting Mac malware rediscovered: SearchPageInjector\/SearchAwesome\" \/>\n\t\t<meta name=\"twitter:description\" content=\"Most people assume that there&#039;s little, if any, Mac malware out there in the wild. Unfortunately, that notion is merely wishful thinking. Malware analysts\u2014even those focused on Mac malware\u2014process so many malware samples that not every new piece of malware necessarily gets its own dedicated article or press release. Such was the case with OSX\/SearchPageInjector,\" \/>\n\t\t<meta name=\"twitter:creator\" content=\"@IntegoSecurity\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"BlogPosting\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/ad-injecting-mac-malware-rediscovered\\\/#blogposting\",\"name\":\"Ad-injecting Mac malware rediscovered: SearchPageInjector\\\/SearchAwesome\",\"headline\":\"Ad-injecting Mac malware rediscovered: SearchPageInjector\\\/SearchAwesome\",\"author\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/author\\\/joshlong\\\/#author\"},\"publisher\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/#organization\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/wp-content\\\/uploads\\\/2018\\\/11\\\/Ad-Injecting-Mac-Malware-Rediscovered-400x260.png\",\"width\":400,\"height\":260,\"caption\":\"Ad Injecting Mac Malware Rediscovered\"},\"datePublished\":\"2018-11-14T11:32:03-08:00\",\"dateModified\":\"2026-08-08T05:11:44-07:00\",\"inLanguage\":\"en-US\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/ad-injecting-mac-malware-rediscovered\\\/#webpage\"},\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/ad-injecting-mac-malware-rediscovered\\\/#webpage\"},\"articleSection\":\"Malware, Malware, OSX\\\/SearchPageInjector, joshlong\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/ad-injecting-mac-malware-rediscovered\\\/#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog#listItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/category\\\/malware\\\/#listItem\",\"name\":\"Malware\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/category\\\/malware\\\/#listItem\",\"position\":2,\"name\":\"Malware\",\"item\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/category\\\/malware\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/ad-injecting-mac-malware-rediscovered\\\/#listItem\",\"name\":\"Ad-injecting Mac malware rediscovered: SearchPageInjector\\\/SearchAwesome\"},\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog#listItem\",\"name\":\"Home\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/ad-injecting-mac-malware-rediscovered\\\/#listItem\",\"position\":3,\"name\":\"Ad-injecting Mac malware rediscovered: SearchPageInjector\\\/SearchAwesome\",\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/category\\\/malware\\\/#listItem\",\"name\":\"Malware\"}}]},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/#organization\",\"name\":\"The Mac Security Blog\",\"description\":\"Keep Macs safe from the dangers of the Internet\",\"url\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/logo2.png\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/ad-injecting-mac-malware-rediscovered\\\/#organizationLogo\",\"width\":122,\"height\":46},\"image\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/ad-injecting-mac-malware-rediscovered\\\/#organizationLogo\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/integogroup\\\/\",\"https:\\\/\\\/x.com\\\/IntegoSecurity\",\"https:\\\/\\\/www.instagram.com\\\/intego_security\\\/\",\"https:\\\/\\\/www.youtube.com\\\/user\\\/IntegoVideo\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/intego\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/author\\\/joshlong\\\/#author\",\"url\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/author\\\/joshlong\\\/\",\"name\":\"Joshua Long\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/ad-injecting-mac-malware-rediscovered\\\/#authorImage\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/ed8c9b8cc8610160efb5aa95bc28a7a0d5a23ce9b8959054305b11094bf0485a?s=96&d=mm&r=g\",\"width\":96,\"height\":96,\"caption\":\"Joshua Long\"}},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/ad-injecting-mac-malware-rediscovered\\\/#webpage\",\"url\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/ad-injecting-mac-malware-rediscovered\\\/\",\"name\":\"Ad-injecting Mac malware rediscovered: SearchPageInjector\\\/SearchAwesome\",\"description\":\"Most people assume that there's little, if any, Mac malware out there in the wild. Unfortunately, that notion is merely wishful thinking. Malware analysts\\u2014even those focused on Mac malware\\u2014process so many malware samples that not every new piece of malware necessarily gets its own dedicated article or press release. Such was the case with OSX\\\/SearchPageInjector,\",\"inLanguage\":\"en-US\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/#website\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/ad-injecting-mac-malware-rediscovered\\\/#breadcrumblist\"},\"author\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/author\\\/joshlong\\\/#author\"},\"creator\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/author\\\/joshlong\\\/#author\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/wp-content\\\/uploads\\\/2018\\\/11\\\/Ad-Injecting-Mac-Malware-Rediscovered-400x260.png\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/ad-injecting-mac-malware-rediscovered\\\/#mainImage\",\"width\":400,\"height\":260,\"caption\":\"Ad Injecting Mac Malware Rediscovered\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/ad-injecting-mac-malware-rediscovered\\\/#mainImage\"},\"datePublished\":\"2018-11-14T11:32:03-08:00\",\"dateModified\":\"2026-08-08T05:11:44-07:00\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/#website\",\"url\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/\",\"name\":\"The Mac Security Blog\",\"description\":\"Keep Macs safe from the dangers of the Internet\",\"inLanguage\":\"en-US\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/#organization\"}}]}\n\t\t<\/script>\n\t\t<!-- All in One SEO Pro -->\r\n\t\t<title>Ad-injecting Mac malware rediscovered: SearchPageInjector\/SearchAwesome<\/title>\n\n","aioseo_head_json":{"title":"Ad-injecting Mac malware rediscovered: SearchPageInjector\/SearchAwesome","description":"Most people assume that there's little, if any, Mac malware out there in the wild. Unfortunately, that notion is merely wishful thinking. Malware analysts\u2014even those focused on Mac malware\u2014process so many malware samples that not every new piece of malware necessarily gets its own dedicated article or press release. Such was the case with OSX\/SearchPageInjector,","canonical_url":"https:\/\/www.intego.com\/mac-security-blog\/ad-injecting-mac-malware-rediscovered\/","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"BlogPosting","@id":"https:\/\/www.intego.com\/mac-security-blog\/ad-injecting-mac-malware-rediscovered\/#blogposting","name":"Ad-injecting Mac malware rediscovered: SearchPageInjector\/SearchAwesome","headline":"Ad-injecting Mac malware rediscovered: SearchPageInjector\/SearchAwesome","author":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/author\/joshlong\/#author"},"publisher":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#organization"},"image":{"@type":"ImageObject","url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2018\/11\/Ad-Injecting-Mac-Malware-Rediscovered-400x260.png","width":400,"height":260,"caption":"Ad Injecting Mac Malware Rediscovered"},"datePublished":"2018-11-14T11:32:03-08:00","dateModified":"2026-08-08T05:11:44-07:00","inLanguage":"en-US","mainEntityOfPage":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/ad-injecting-mac-malware-rediscovered\/#webpage"},"isPartOf":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/ad-injecting-mac-malware-rediscovered\/#webpage"},"articleSection":"Malware, Malware, OSX\/SearchPageInjector, joshlong"},{"@type":"BreadcrumbList","@id":"https:\/\/www.intego.com\/mac-security-blog\/ad-injecting-mac-malware-rediscovered\/#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"https:\/\/www.intego.com\/mac-security-blog#listItem","position":1,"name":"Home","item":"https:\/\/www.intego.com\/mac-security-blog","nextItem":{"@type":"ListItem","@id":"https:\/\/www.intego.com\/mac-security-blog\/category\/malware\/#listItem","name":"Malware"}},{"@type":"ListItem","@id":"https:\/\/www.intego.com\/mac-security-blog\/category\/malware\/#listItem","position":2,"name":"Malware","item":"https:\/\/www.intego.com\/mac-security-blog\/category\/malware\/","nextItem":{"@type":"ListItem","@id":"https:\/\/www.intego.com\/mac-security-blog\/ad-injecting-mac-malware-rediscovered\/#listItem","name":"Ad-injecting Mac malware rediscovered: SearchPageInjector\/SearchAwesome"},"previousItem":{"@type":"ListItem","@id":"https:\/\/www.intego.com\/mac-security-blog#listItem","name":"Home"}},{"@type":"ListItem","@id":"https:\/\/www.intego.com\/mac-security-blog\/ad-injecting-mac-malware-rediscovered\/#listItem","position":3,"name":"Ad-injecting Mac malware rediscovered: SearchPageInjector\/SearchAwesome","previousItem":{"@type":"ListItem","@id":"https:\/\/www.intego.com\/mac-security-blog\/category\/malware\/#listItem","name":"Malware"}}]},{"@type":"Organization","@id":"https:\/\/www.intego.com\/mac-security-blog\/#organization","name":"The Mac Security Blog","description":"Keep Macs safe from the dangers of the Internet","url":"https:\/\/www.intego.com\/mac-security-blog\/","logo":{"@type":"ImageObject","url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2026\/08\/logo2.png","@id":"https:\/\/www.intego.com\/mac-security-blog\/ad-injecting-mac-malware-rediscovered\/#organizationLogo","width":122,"height":46},"image":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/ad-injecting-mac-malware-rediscovered\/#organizationLogo"},"sameAs":["https:\/\/www.facebook.com\/integogroup\/","https:\/\/x.com\/IntegoSecurity","https:\/\/www.instagram.com\/intego_security\/","https:\/\/www.youtube.com\/user\/IntegoVideo","https:\/\/www.linkedin.com\/company\/intego"]},{"@type":"Person","@id":"https:\/\/www.intego.com\/mac-security-blog\/author\/joshlong\/#author","url":"https:\/\/www.intego.com\/mac-security-blog\/author\/joshlong\/","name":"Joshua Long","image":{"@type":"ImageObject","@id":"https:\/\/www.intego.com\/mac-security-blog\/ad-injecting-mac-malware-rediscovered\/#authorImage","url":"https:\/\/secure.gravatar.com\/avatar\/ed8c9b8cc8610160efb5aa95bc28a7a0d5a23ce9b8959054305b11094bf0485a?s=96&d=mm&r=g","width":96,"height":96,"caption":"Joshua Long"}},{"@type":"WebPage","@id":"https:\/\/www.intego.com\/mac-security-blog\/ad-injecting-mac-malware-rediscovered\/#webpage","url":"https:\/\/www.intego.com\/mac-security-blog\/ad-injecting-mac-malware-rediscovered\/","name":"Ad-injecting Mac malware rediscovered: SearchPageInjector\/SearchAwesome","description":"Most people assume that there's little, if any, Mac malware out there in the wild. Unfortunately, that notion is merely wishful thinking. Malware analysts\u2014even those focused on Mac malware\u2014process so many malware samples that not every new piece of malware necessarily gets its own dedicated article or press release. Such was the case with OSX\/SearchPageInjector,","inLanguage":"en-US","isPartOf":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#website"},"breadcrumb":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/ad-injecting-mac-malware-rediscovered\/#breadcrumblist"},"author":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/author\/joshlong\/#author"},"creator":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/author\/joshlong\/#author"},"image":{"@type":"ImageObject","url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2018\/11\/Ad-Injecting-Mac-Malware-Rediscovered-400x260.png","@id":"https:\/\/www.intego.com\/mac-security-blog\/ad-injecting-mac-malware-rediscovered\/#mainImage","width":400,"height":260,"caption":"Ad Injecting Mac Malware Rediscovered"},"primaryImageOfPage":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/ad-injecting-mac-malware-rediscovered\/#mainImage"},"datePublished":"2018-11-14T11:32:03-08:00","dateModified":"2026-08-08T05:11:44-07:00"},{"@type":"WebSite","@id":"https:\/\/www.intego.com\/mac-security-blog\/#website","url":"https:\/\/www.intego.com\/mac-security-blog\/","name":"The Mac Security Blog","description":"Keep Macs safe from the dangers of the Internet","inLanguage":"en-US","publisher":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#organization"}}]},"og:locale":"en_US","og:site_name":"The Mac Security Blog - Keep Macs safe from the dangers of the Internet","og:type":"article","og:title":"Ad-injecting Mac malware rediscovered: SearchPageInjector\/SearchAwesome","og:description":"Most people assume that there's little, if any, Mac malware out there in the wild. Unfortunately, that notion is merely wishful thinking. Malware analysts\u2014even those focused on Mac malware\u2014process so many malware samples that not every new piece of malware necessarily gets its own dedicated article or press release. Such was the case with OSX\/SearchPageInjector,","og:url":"https:\/\/www.intego.com\/mac-security-blog\/ad-injecting-mac-malware-rediscovered\/","article:published_time":"2018-11-14T19:32:03+00:00","article:modified_time":"2026-08-08T12:11:44+00:00","article:publisher":"https:\/\/www.facebook.com\/integogroup\/","twitter:card":"summary_large_image","twitter:site":"@IntegoSecurity","twitter:title":"Ad-injecting Mac malware rediscovered: SearchPageInjector\/SearchAwesome","twitter:description":"Most people assume that there's little, if any, Mac malware out there in the wild. Unfortunately, that notion is merely wishful thinking. Malware analysts\u2014even those focused on Mac malware\u2014process so many malware samples that not every new piece of malware necessarily gets its own dedicated article or press release. Such was the case with OSX\/SearchPageInjector,","twitter:creator":"@IntegoSecurity"},"aioseo_meta_data":[],"aioseo_breadcrumb":"<div class=\"aioseo-breadcrumbs\"><span class=\"aioseo-breadcrumb\">\n\t<a href=\"https:\/\/www.intego.com\/mac-security-blog\" title=\"Home\">Home<\/a>\n<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t<a href=\"https:\/\/www.intego.com\/mac-security-blog\/category\/malware\/\" title=\"Malware\">Malware<\/a>\n<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\tAd-injecting Mac malware rediscovered: SearchPageInjector\/SearchAwesome\n<\/span><\/div>","aioseo_breadcrumb_json":[{"label":"Home","link":"https:\/\/www.intego.com\/mac-security-blog"},{"label":"Malware","link":"https:\/\/www.intego.com\/mac-security-blog\/category\/malware\/"},{"label":"Ad-injecting Mac malware rediscovered: SearchPageInjector\/SearchAwesome","link":"https:\/\/www.intego.com\/mac-security-blog\/ad-injecting-mac-malware-rediscovered\/"}],"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts\/84208","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/users\/14"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/comments?post=84208"}],"version-history":[{"count":8,"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts\/84208\/revisions"}],"predecessor-version":[{"id":106306,"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts\/84208\/revisions\/106306"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/media\/84232"}],"wp:attachment":[{"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/media?parent=84208"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/categories?post=84208"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/tags?post=84208"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}