BitTorrent app Transmission once again source of macOS malware
Once again, BitTorrent client Transmission has distributed malware to some users through an altered installer, with downloaders of the software on Aug. 28 and 29 probably infected by the "Keydnap" package.
The previous version of Keydnap required users to click on a maliciously formed file, which then opened the installer in Terminal. The malware then waited to install until the next app was launched, and popped up a dialog box asking for authentication.
When packaged with Transmission, the malware needed no second app to execute, nor did it require further user authentication beyond what was needed to install Transmission. Additionally, since the Transmission app was properly signed, Gatekeeper allowed the execution of the malware installation without complaint.