The XCSSET malware has reappeared with an updated version, v40, after a period of inactivity. This new variant targets macOS users by compromising Xcode projects and GitHub repositories, injecting malicious downloader scripts into benign files. Developers become infected when they download and build these compromised projects.
Researchers at Palo Alto Networks' Unit 42 observed XCSSET version 40 in two attack waves in mid-April and early May. Once a developer's system is infected, XCSSET can compromise other Xcode projects on the system and spread further through shared source code. The malware follows a four-stage infection chain before deploying 17 modules for various malicious activities.
Version 40 of XCSSET introduces two new modules: a Chrome hijacker and a Telegram trojanizer. The Chrome hijacker wraps the browser in a malicious launcher, enabling the Chrome DevTools Protocol to fetch JavaScript from the attacker's command-and-control infrastructure. This allows for interception of web traffic, credentials, cookies, and MetaMask transactions, as well as system command execution via a fileless reverse shell.
The Telegram trojanizer deletes the legitimate Telegram Desktop application and replaces it with a malicious version, potentially enabling interception of victim communications.
XCSSET has been targeting macOS systems since at least 2021, previously exploiting zero-day vulnerabilities. In 2025, Microsoft warned of an XCSSET campaign using compromised Xcode projects for distribution and identified a variant with cryptocurrency-theft capabilities. The current version's capabilities include credential theft, keystroke logging, clipboard manipulation, browser hijacking, and data exfiltration, posing a significant risk to macOS developers and their users.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
A new version of the XCSSET malware, v40, is infecting macOS users by injecting downloader scripts into Xcode projects within vulnerable GitHub repositories. This updated variant includes enhanced evasion techniques and new modules for Chrome hijacking and Telegram trojanizing, allowing for credential theft, data exfiltration, and cryptocurrency manipulation.