The chain starts with user-assisted execution, not an iCloud or Calendar exploit. Kaspersky reports ClickFix-style lures, cracked software, and fake applications such as the Toria cryptocurrency wallet. Once the first-stage downloader is executing, one variant retrieves a public caldav.icloud.com/published/... calendar file, creates an anonymous pipe, starts zsh -s, and streams the calendar into the shell as standard input. Most iCalendar lines fail as commands; shell syntax placed after the DESCRIPTION: field executes and retrieves the next-stage archive. That makes the calendar a one-way command dead drop after code execution, not the initial compromise and not evidence that opening Calendar infects a Mac. The archive contains an application-bundle dropper; reported follow-on behavior includes quarantine removal, ad-hoc signing, execution of further stages, and delivery of MacSync components.
For detection, the decisive signal is the process-and-network sequence, not traffic to iCloud alone: a non-Apple or user-writable executable accesses a public CalDAV URL, spawns /bin/zsh -s, and is followed by archive/application writes, quarantine-attribute removal, ad-hoc signing, or additional downloads. Persistence indicators reported by Kaspersky include a LaunchAgent named com.apple.finder.agent, execution of .repair-run through .zshrc, and similar injections into global Git pre-commit and post-checkout hooks. Those artifacts distinguish infection from ordinary Calendar synchronization far better than blocking icloud.com, which would be noisy and disruptive.
I would rate the campaign High, not Critical, on the published evidence alone. Credential, wallet, developer-secret, and Keychain theft combined with persistent remote execution is serious, but the handoff does not establish zero-click compromise, broad prevalence, victim counts, actor attribution, or confirmed end-to-end theft across the reported population. The reporting also says some attacker-hosted scripts were unavailable for analysis, so their exact contents remain unknown. It is likewise unverified that every MacSync infection uses the calendar mechanism or deploys the Objective-C backdoor; the public-calendar path is an observed variant. A Critical response priority is justified only for hosts where this execution chain or persistence is detected.
The highest-yield hunt tonight is: find zsh -s executions whose parent is an unsigned, ad-hoc-signed, or user-writable executable, then correlate within minutes with that parent accessing caldav.icloud.com/published/ and with .repair-run, com.apple.finder.agent, .zshrc, or global Git-hook modifications. That sequence is the malware’s narrow choke point—the equivalent of catching the instruction pointer as it crosses from calendar data into executable shell input.