Skip to content

macOS 26.3 arm64: Node v24.19.0 checksum-matched artifacts fail signature verification #5173

Description

@hajidunn-coder

Node.js Version

v24.19.0 (official artifact label; not executed)

NPM Version

UNKNOWN — neither artifact has been executed or installed

Operating System

macOS 26.3 (build 25D2125), arm64

Subsystem

Other

Description

I am verifying official Node.js v24.19.0 macOS artifacts before execution or installation. On macOS 26.3 (build 25D2125), the following checks observed on 2026-10-07 UTC failed:

  • /usr/bin/codesign --verify --strict --verbose=2 ./node: exit 1, invalid signature (code or signature have been modified), In architecture: arm64.
  • /usr/sbin/pkgutil --check-signature ./node-v24.19.0.pkg: exit 1, Status: invalid signature.

The archive and installer match the observed official checksum values. I have not cryptographically verified the checksum file's detached PGP signature.

Artifact SHA256
node-v24.19.0-darwin-arm64.tar.gz 8294b7aa9b03997481c06babf1e8b270c859358f27da57a11509afe537ac381d
extracted node member, 121306800 bytes 27db838bb204ef7c21df2931f5656e4c8fb32e6e947f363a402b49714d32b5b1
node-v24.19.0.pkg, 92775015 bytes 13ecebfefa0234e3d618b4a0af8c5803bdeedab30b84ee37cccafb7276d90a0e

Read-only signature display returned exit 0 with Identifier=node, Format=Mach-O thin (arm64), embedded CodeDirectory v20500, flags0x10000(runtime), Authority=(unavailable), TeamIdentifier=HX7739G8FX, and CMSDigest 30e89192573a4bdc040db0cc5aeb461c6ca49b312ed35ae76ea86d09c7c3c809. This is display output, not a successful signature verification. The node hash measured afterward matched the member hash above; no fresh before/after identity interval was captured for that display.

Neither artifact has been executed or installed. No signature, quarantine, keychain or clock changes have been made as a remediation. I have not concluded that the cause is artifact corruption, certificate trust or an OS defect.

What signer/certificate chain and verification result are expected for these exact artifacts on this host, and what minimal supported diagnostic should distinguish the possible causes? If maintainers identify an artifact problem, please identify an official corrected artifact and verification instructions. Sanitized command paths above stand in for the original local paths.

Minimal Reproduction

No response

Output

No response

Before You Submit

  • I have looked for issues that already exist before submitting this
  • My issue follows the guidelines in the README file, and follows the 'How to ask a good question' guide at https://stackoverflow.com/help/how-to-ask

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions