← All detection heuristics · Script
critical
MACOS_ZSH_LOADER
What it means
File bytes contain a base64/gzip shell loader executed with zsh.
Why it fires
The file contains a shell command or embedded shell script that decodes a URL or gzip-compressed stage and executes it with zsh. The decoded stage is treated as malware when it retrieves and executes AppleScript via osascript, posts host/locale telemetry, or uses geofencing logic. The detector runs across submitted file types because this loader can be carried by a misnamed document, script, HTML, RTF body, or wrapper.
Other Script heuristics
SCRIPT_WSH_OBFUSCATED WINDOWS_PS_ADDTYPE_WINAPI_TAMPER LNK_POWERSHELL_BIGINT_NETWORK_ENDPOINT WINDOWS_PS_SCREENSHOT_UPLOAD_EXFIL WINDOWS_SCRIPT_CERTUTIL_RUNDLL_CHAIN SCRIPT_WSH_STREAM_WRITE_RUN_CHAIN WINDOWS_SCHEDULED_TASK_SCRIPT_EXEC WINDOWS_SCRIPT_BASE64_BINARY_DROPPER LNK_SCRIPT_DOWNLOADER SCRIPT_HEAVY_STRING_DECODER_OBFUSCATION SCRIPT_WSH_MASQUERADE LNK_HIDDEN_SCRIPT_EXEC