After working on it a bit, we have a fix for a recent attack against that leverages AppleScript. Here's the writeup, and a link to the forum thread!

https://ifin-intel.org/blog/applescript/