2/ The loader is written in AppleScript and branded as a “Microsoft Teams Live SDK update”. To look trustworthy, it first opens a legitimate Microsoft Teams page in the background (the “What’s new” or documentation page) so a user sees something normal in their browser ...
3/ The malicious part lives here

It uses 'curl -L -k' command to download a second-stage script from: https[:]//support.ms-live[.]com/519738/check
Then executes the downloaded content via run script in AppleScript.
4/ We’ve previously seen related loaders on VirusTotal:
9135fb9e74bdb39828bfecf7919430062ce482a523999bd7ff1a368038f32371
14aba88b5f87ab9415bbca855d24abc3f151b819302930897e71e2626e823271
81c4ce82fe26e333a46e8a3d876e35b39725bda0a47f9c37ffc956d37da2d8fa