Invental/ Research

Research.

First-party technical analysis, published because the primary evidence exists nowhere else. Malware teardowns, code-signing and supply-chain work — the questions where the honest answer is a verifiable fact rather than an opinion.

01 · piece published Static analysis only Disclosure before publication Montevideo, UY
Published
macOS · Code signing · 29 Aug 2026

Can notarized macOS software still be malware?

Yes. Apple's notary service scans the package you submit; it does not constrain what that package does once it runs. A live, signed, notarized installer that passes Gatekeeper with no warning — and fetches its payload as root at install time. With the verification output and the six-line dropper.

Read the analysis
Pattern · 01 Notarized.
Still malware.

How this work is done

Corrections and takedown

If something here is wrong, we want to fix it rather than defend it. That includes misidentification — a stolen or resold signing certificate makes its registered holder a victim, not a distributor, which is why this section names Team IDs and never people.

Write to hi@invental.co with the page and the specific claim. Corrections are made on the page itself and dated. Takedown requests are read by a person, not a form.

— Invental · software studio · Montevideo, UY