Apple’s XProtect security software has been silently updated to include signatures that detect Windows PE files and Windows executables that can run on Macs by utilizing the Mono.NET framework. XProtect is Apple’s built in antivirus software that offers real time protection on Mac. In order to protect users, XProtect utilizes signatures built from Yara rules that target known threats to Mac users. Two new signatures were released on April 19th, 2019 that when used together can detect adware bundles that contain Windows. PE files, and MACOS.d1e06b8, which is used to detected a specially crafted Windows.executable.
Source: https://www.bleepingcomputer.com/news/security/apple-updates-xprotect-to-block-windows-malware-on-macs/