The nature of open-source software often imparts it with a degree of trust, since users can read its code to check for hidden nasties and subsequently patch them out if they are found. But according to security firm Trend Micro, bad actors have taken open-source app ResignTool and modified it to steal your Keychain data, which can include passwords and credit card info.
According to the report, the malware version of ResignTool is frequently distributed on filesharing websites, perhaps targeting users who want to save money by downloading cracked software. That could be a fatal error, however, given how much sensitive data is stored in the Keychain.