Forum Moderators: travelin cat
The trick involved packing a symlink (symbolic link) inside an archive file and having the symlink link back to an attacker-controlled Network File System (NFS) server.
Cavallarin found that Gatekeeper wouldn't scan these types of files, and would allow users to execute the symlinks. If the symlinks were malicious, attackers could run harmful code on victims' macOS systems.