Proprietary 1998-10-01 · 4 days ·Malware Distribution, Nuisance

CorelDRAW Mac CDs carried AutoStart worm

Corel recalled the second pressing of CorelDRAW 8.0 for Mac OS after CD-ROMs carried AutoStart 9805-D. The worm abused QuickTime AutoStart on classic Mac OS.

Story

In October 1998, Corel recalled the second pressing of CorelDRAW 8.0 for Mac OS. Virus Bulletin reported that the affected CD-ROMs carried the D strain of AutoStart 9805 and that Corel said it had retrieved 95% of the infected discs during the first week of October.

The delivery path was plain physical distribution. A user mounted a trusted Corel CD-ROM on a PowerPC Mac with QuickTime AutoStart enabled. The operating system could then launch an application from the volume before the user made a security decision.

AutoStart 9805 lived in removable media and the classic Mac OS Extensions path. Earlier variants used an invisible DB file and a hidden Desktop Print Spooler component, then copied themselves to other mounted HFS or HFS+ volumes. The D strain was less destructive than the original line, but the carrier was official product media.

Corel responded by recalling the affected batch and issuing public guidance. The incident belongs with the older physical-media failures: the package was authentic, the label was trusted, and the bytes on the disc were not clean.

Affected Artifacts

Observed
1998-10-01 to 1998-10-05
Compromised Versions
Fixed
Not listed
Evidence
malware: AutoStart 9805-D, malware: AutoStart 9805, platform: classic Mac OS, platform: PowerPC Macintosh with QuickTime AutoStart enabled , +3 more
  • Virus Bulletin reported that Corel said it had retrieved 95% of the infected CDs during the first week of October 1998.
  • The date window is bounded to the first week of October 1998 and the October 5, 1998 public report; the exact pressing or shipment start date was not found.
  • Virus Bulletin described AutoStart 9805-D as removing earlier versions of itself and not intentionally damaging files, unlike more destructive AutoStart 9805 variants.

Incident Context

Cause
Contaminated Physical Media
Transitive
No

External References

Source record: proprietary/coreldraw-mac/meta.yaml