78

xar (macOS .pkg) file signature

Magic number at the start of the file · xar!

78 61 72 21

An eXtensible ARchive starts with the four ASCII bytes xar!, then a 2-byte header size and the archive version. macOS flat installer packages (.pkg) are xar archives, which is why a .pkg begins with xar! rather than a ZIP or DMG header.

Hex signature
78 61 72 21
Offset
0 (start of file)
ASCII
xar!
Length
4 bytes

What this magic number means

A magic number is a short, fixed run of bytes at a known position that tells a program what a file really is, no matter what the filename says. If a file starts with the bytes 78 61 72 21 (the text xar!), it is a xar (macOS .pkg) file.

After the header comes a zlib-compressed XML table of contents describing every file in the archive, then the file data itself. Reading that table is how installers list a package's contents before extracting anything.

The .pkg extension is reused by unrelated software, so the bytes matter: a macOS installer package starts with xar!, while other .pkg files (game data, Solaris packages) do not and are simply a different format wearing the same name.

What each byte of 78 61 72 21 means

Here is the signature byte by byte, the way a hex editor shows it: the position in the file, the value in hex and in decimal, and the character that value stands for in ASCII. Bytes with no printable character show a dot.

Byte offsetHexDecimalASCII
078120x
16197a
272114r
32133!

Formats that use the 78 61 72 21 signature

These file types in our database carry this signature:

It is also seen in: XAR, SafariExtz.

How to check a file's signature

You can read the bytes of any file yourself. They are shown in hex, the same way this page lists them.

Linux & macOS

  • xxd -l 16 example.pkg
  • hexdump -C -n 16 example.pkg
  • file example.pkg

Windows (PowerShell)

  • Format-Hex -Path example.pkg -Count 16

Python

  • open("example.pkg","rb").read(4).hex()

In your browser

Frequently asked questions

What is the xar (macOS .pkg) file signature?

xar (macOS .pkg) files start with the hex bytes 78 61 72 21 (xar! in ASCII). This magic number identifies the format regardless of the file's name or extension.

How do I check a file's magic number?

Open the file in a hex editor, or run a command such as xxd -l 16 example.pkg on Linux or macOS, or Format-Hex -Path example.pkg -Count 16 in Windows PowerShell, and read the first bytes.

Can a file fake the xar (macOS .pkg) signature?

Renaming a file does not change its bytes, so the extension can lie but the signature usually cannot. A genuine xar (macOS .pkg) file has these exact bytes; a file with the wrong bytes is not really xar (macOS .pkg), whatever its name says.

Related signatures

Sources

Reuse this signature

This entry is part of the WhatFileType file signature reference, published under a CC BY 4.0 licence with the full provenance for every entry, a copy-paste embed and a JSON export. Credit WhatFileType and the data is yours to republish.