Close Menu
NCIJ Network NCIJ Network
    What's Hot

    A New Device Eases One of the Most Annoying Parts of Routine Physicals

    August 5, 2026

    NVIDIA Releases Alpamayo 2 Super: A 34B Open Vision-Language-Action Model for Robotaxis and Autonomous Driving Under OpenMDW-1.1

    August 5, 2026

    Over 400 NPM Packages Infected in ChainDrop Supply Chain Attack

    August 5, 2026
    Facebook X (Twitter) Instagram
    Trending
    • A New Device Eases One of the Most Annoying Parts of Routine Physicals
    • NVIDIA Releases Alpamayo 2 Super: A 34B Open Vision-Language-Action Model for Robotaxis and Autonomous Driving Under OpenMDW-1.1
    • Over 400 NPM Packages Infected in ChainDrop Supply Chain Attack
    • Hester ‘Crypto Mom’ Peirce Optimistic About Clarity Act
    • Giant waves are sweeping Mars’ atmosphere into space
    • How rescued orangutans are rebuilding a new wild population in Sumatra
    • As Spain grieves, recurrent heatwaves stir fears of more wildfires | Weather News
    • Europe has the defense budget. The test now is delivery. – POLITICO
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Wednesday, August 5
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    New XCSSET variant targets macOS devs via compromised Xcode projects

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 5, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    A new version of the XCSSET malware is targeting thousands of macOS users through compromised Xcode projects and GitHub repositories.

    Xcode is the official software development kit (SDK) for creating, testing, and publishing software for all Apple’s platforms.

    After months of inactivity, XCSSET has resurfaced with an updated version, v40, that features enhanced evasion techniques and introduces two new components, researchers have found.

    image

    Researchers at Palo Alto Networks’ Unit 42, who analyzed the infection chain, say the threat actor spreads the malware by compromising vulnerable Git repositories and injecting a downloader script into benign files within Xcode projects.

    Developers downloading the compromised projects become infected upon building them, allowing XCSSET to compromise every other Xcode project on the system and propagate further through shared source code.

    Infected Xcode project
    Infected Xcode project
    Source: Unit 42

    Unit 42 researchers observed XCSSET version 40 used in two distinct attack waves in mid-April and in early May.

    XCSSET has targeted macOS systems since at least 2021 and has, in some cases, exploited zero-day vulnerabilities in its attacks.

    In September 2025, Microsoft warned of an XCSSET campaign that used compromised Xcode projects as a distribution mechanism. The company had also previously identified a variant of the malware that introduced cryptocurrency-theft capabilities.

    In the attacks analyzed by Unit 42, XCSSET follows a four-stage infection chain before deploying 17 separate modules that enable credential theft, keystroke logging, clipboard manipulation, browser hijacking, and data exfiltration.

    XCSSET infection chain
    XCSSET infection chain
    Source: Unit 42

    According to the researchers, the newest XCSSET version features two new modules, namely a Chrome hijacker and a Telegram trojanizer.

    The hijacker wraps the Chrome browser in a malicious launcher and enables the Chrome DevTools Protocol (CDP) on a local port to fetch JavaScript from the attacker’s command-and-control (C2) infrastructure.

    The code allows the attackers to intercept web traffic, including credentials, cookies, and MetaMask transactions, which can be manipulated on the fly to divert payments.

    Additionally, the hijacker module enables system command execution via a fileless reverse shell, which Google blocks in Chrome for Windows and is currently working to extend these protections to macOS.

    Chrome hijacking mechanism
    Chrome hijacking mechanism
    Source: Unit 42

    The Telegram trojanizer deletes the legitimate Telegram Desktop application on infected systems and replaces it with a malicious version, potentially used for intercepting victims’ communications.

    Unit 42 could not retrieve its encrypted configuration; hence, its exact functionality remains unknown.

    The researchers also highlighted XCSSET’s new detection-evasion measures, including periodically re-compiling the loader on the C2 server, using separate encryption keys for inbound and outbound communications, and obfuscating function names, variables, and strings, with build-unique ciphers.

    The malware aggressively attempts to disable macOS security such as XProtect, MRT, TCC, and Rapid Security Response, terminates Apple’s CloudTelemetryService, and prevents XProtect signature updates.

    Unit 42 recommends monitoring for anomalous AppleScript activity, unauthorized browser modifications, suspicious macOS defaults domains, and ad hoc-signed applications that bypass Gatekeeper.

    To defend against the latest version of XCSSET, the researchers also recommend scanning open-source dependencies to prevent compromised repositories from entering software development pipelines.


    article image

    Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

    The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

    Get the whitepaper

    Compromised devs macOS Projects targets variant Xcode XCSSET
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Over 400 NPM Packages Infected in ChainDrop Supply Chain Attack

    QuickFox Supply Chain Attack Delivers FDMTP Backdoor via Trojanized Windows Installer

    Zenity Raises $125 Million in Series C Funding

    AI Notetaker Exposes Government, Corporate Video Calls

    OpenAI, Anthropic AI agents targeted real people and systems in cyber tests

    Smoke#Screen RMM Takeover Gambit Exposes Threat Actor Playbook

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    A New Device Eases One of the Most Annoying Parts of Routine Physicals

    August 5, 2026

    NVIDIA Releases Alpamayo 2 Super: A 34B Open Vision-Language-Action Model for Robotaxis and Autonomous Driving Under OpenMDW-1.1

    August 5, 2026

    Over 400 NPM Packages Infected in ChainDrop Supply Chain Attack

    August 5, 2026

    Hester ‘Crypto Mom’ Peirce Optimistic About Clarity Act

    August 5, 2026
    Latest Posts

    Oil prices hit $100 for the first time since May

    July 23, 2026

    Pew Survey: China May Be Liked More, but It Is Celebrating a Race It Never Ran

    July 23, 2026

    Yinson Production and PTSC’s FSO heads off to Southeast Asian oil project

    July 23, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    A New Device Eases One of the Most Annoying Parts of Routine Physicals

    August 5, 2026

    NVIDIA Releases Alpamayo 2 Super: A 34B Open Vision-Language-Action Model for Robotaxis and Autonomous Driving Under OpenMDW-1.1

    August 5, 2026

    Over 400 NPM Packages Infected in ChainDrop Supply Chain Attack

    August 5, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.