Is this macOS login item or background item malware?
The name in System Settings is the code signer, not the plist. Find the launchd plist behind it, read the program it runs, and verify that program's code signature and Team ID against the vendor's own apps on your machine. A valid vendor signature on a vendor-labelled entry closes the case. Anything unsigned, ad-hoc signed, failing verification or signed by the wrong team stays open. npx am-i-hacked --system --verbose does these checks for every login item at once.
"Background Items Added" is not an indicator by itself
macOS shows that notification whenever an item is registered. Vendor updaters re-register after every update. System Settings > General > Login Items & Extensions groups entries by the signing developer's name, and shows "Item from unidentified developer" when there is no valid Developer ID.
Check one item by hand
- Find the plist.
Match on the vendor prefix (ls -la ~/Library/LaunchAgents /Library/LaunchAgents /Library/LaunchDaemonscom.google.*) or a recent modification time. - Read it.
plutil -p <plist>. NoteLabel,ProgramorProgramArguments,RunAtLoad,KeepAliveandEnvironmentVariables. Red flags without any signature check: acom.apple.*label outside/System,DYLD_INSERT_LIBRARIESorNODE_OPTIONSin the environment, or a program that no longer exists. - Verify the signature of a compiled program:
codesign -dv --verbose=2 <program> codesign --verify --deep --strict <program> codesign -dv /Applications/<Vendor>.app 2>&1 | grep TeamIdentifier # the vendor's real Team ID - Read scripts without running them. If the program is
/bin/shornode, the payload is the script. Look for clipboard or screen capture (pbpaste,screencapture) paired with an exfiltration endpoint (api.telegram.org, Discord or Slack webhooks).
Verdicts
| Evidence | Verdict |
|---|---|
| Vendor label, valid signature, vendor Team ID | Legitimate. Close. |
| Vendor label, another Team ID or unsigned | HIGH: impersonation. Preserve and escalate. |
| Signature fails verification | MEDIUM: modified after signing. |
Unsigned or ad-hoc, in Application Support, Caches, Downloads, /tmp or /Users/Shared | MEDIUM: confirm you installed it. |
| Unsigned or ad-hoc elsewhere, such as Homebrew services | INFO: usually developer tooling. |
| Capture paired with exfiltration in the script | HIGH, whatever the signature. |
Automate it
npx am-i-hacked --system --verbose
The verbose inventory lists every login item with its signer and Team ID, using the same severities as the table above. Expected Team IDs come from a table of vendors read from genuine apps, then from installed apps with the same bundle-id prefix. The login-item-triage skill walks an agent through the manual method, including which commands show an OS prompt.
Before you remove anything
Copy the plist and the program's folder, record their SHA-256 hashes and modification times, then stop the item with launchctl bootout. If capture was confirmed, rotate secrets from a clean device.