Intego, makers of VirusBarrier and other security software for the Macintosh, issued a security alert for Mac users on Thursday, advising them about the existence of a new Trojan Horse, which they’ve named OSX.Trojan.iServices.A. This new Trojan Horse can be found in pirated copies of Apple’s iWork ‘09 application suite, which has been downloaded over 20,000 times, according to Intego’s numbers.
When installing an infected pirated copy of iWork ‘09, an extra iWorkServices package is installed; this installation begins as soon as the user launches the iWork ‘09 installer. This package is installed as a system-wide startup item, where it has read-write permissions as root. In other words, this code can do anything to any part of the system, with full authorization.