OSX.EvilEgg is Malwarebytes’detection name for a macOs app named CoinTicker that installs two different backdoors.
The CoinTicker app, on the surface, appears to be a legitimate application that could potentially be useful to someone who has invested in cryptocurrencies. The app puts an icon in the menu bar that gives information about the current price of Bitcoin.
Type and source of infection
When OSX.EvilEgg is launched, the app will download and install components of two different open-source backdoors: EvilOSX and EggShell.
It seems likely that OSX.EvilEgg is meant to be used to gain access to users cryptocurrency wallets, for the purpose of stealing coins.
Malwarebytes for Mac detects and removes OSX.EvilEgg.
Python script: plQqVfeJvGo
User launch agent: com.apple.EOFHXpQvqhr.plist
Network connections: 126.96.36.199:2280 188.8.131.52:1339