← All stories
● Covered by 1 source · 1 reportMedium impact1 negative

New XCSSET v40 malware targets macOS developers via compromised Xcode projects

🔄 Updated 1d ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • XCSSET v40 targets macOS developers through compromised Xcode projects.
  • Malware spreads when developers build infected projects from GitHub.
  • New modules include a Chrome hijacker and a Telegram trojanizer.
  • Capabilities include credential theft, keystroke logging, and cryptocurrency manipulation.

XCSSET Malware Resurfaces

The XCSSET malware has reappeared with an updated version, v40, after a period of inactivity. This new variant targets macOS users by compromising Xcode projects and GitHub repositories, injecting malicious downloader scripts into benign files. Developers become infected when they download and build these compromised projects.

Infection Mechanism and Propagation

Researchers at Palo Alto Networks' Unit 42 observed XCSSET version 40 in two attack waves in mid-April and early May. Once a developer's system is infected, XCSSET can compromise other Xcode projects on the system and spread further through shared source code. The malware follows a four-stage infection chain before deploying 17 modules for various malicious activities.

New Modules and Capabilities

Version 40 of XCSSET introduces two new modules: a Chrome hijacker and a Telegram trojanizer. The Chrome hijacker wraps the browser in a malicious launcher, enabling the Chrome DevTools Protocol to fetch JavaScript from the attacker's command-and-control infrastructure. This allows for interception of web traffic, credentials, cookies, and MetaMask transactions, as well as system command execution via a fileless reverse shell.

The Telegram trojanizer deletes the legitimate Telegram Desktop application and replaces it with a malicious version, potentially enabling interception of victim communications.

Historical Context and Impact

XCSSET has been targeting macOS systems since at least 2021, previously exploiting zero-day vulnerabilities. In 2025, Microsoft warned of an XCSSET campaign using compromised Xcode projects for distribution and identified a variant with cryptocurrency-theft capabilities. The current version's capabilities include credential theft, keystroke logging, clipboard manipulation, browser hijacking, and data exfiltration, posing a significant risk to macOS developers and their users.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~7 min · 6 stories · Aug 15

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

A new version of the XCSSET malware, v40, is infecting macOS users by injecting downloader scripts into Xcode projects within vulnerable GitHub repositories. This updated variant includes enhanced evasion techniques and new modules for Chrome hijacking and Telegram trojanizing, allowing for credential theft, data exfiltration, and cryptocurrency manipulation.