Fake installer and malvertising campaigns now span Windows and macOS alike, using trojanized DMG and EXE files, delayed activation, and hardware-gated payloads to harvest browser, keychain, and developer credentials while still installing the expected app.