XCSSET Malware Targets macOS Developers Through Xcode Projects

XCSSET Malware Targets macOS Developers Through Xcode Projects

First seen 19 May 2026, 14:50 UTC Sg.Finance.YahooMorningstarwww.prnewswire.comMarkets.Businessinsiderwww.globenewswire.com 92% similarity 69.5

Article Content

Browse articles
ThreatCluster

The ADEX security team has published a case study on an active XCSSET malware infection affecting an iOS app development studio. XCSSET, a modular macOS malware identified in 2020, embeds itself in Xcode project files and executes during the build process without alerting the developer. This malware is capable of stealing credentials from various sources, including browsers and cryptocurrency wallets, and can propagate itself by injecting into other Xcode projects. The infection is particularly dangerous as it operates silently, inheriting the developer's permissions. The ADEX team captured the malware using a behavioral analysis technique, revealing its complex capabilities, including clipboard hijacking and ransomware functionality. The malware's evolution continues, with new methods documented as recently as 2025. The case study emphasizes the need for heightened security awareness among developers.

Key Points: • XCSSET malware infects Xcode projects, executing during the build process. • The malware steals sensitive credentials and can propagate to other projects automatically. • ADEX's analysis highlights the silent nature of the infection and its advanced capabilities.

ThreatCluster AI

Timeline

2020-06-01
XCSSET malware first identified
XCSSET was first discovered as a modular macOS malware targeting developers through Xcode.
Article 1
2025-01-01
New injection methods documented
Microsoft reported new injection techniques used by XCSSET, indicating its ongoing evolution.
Article 2
2026-05-19
ADEX publishes case study on live infection
ADEX released a detailed analysis of a live XCSSET infection affecting an iOS app development studio.
Article 4

Community

Browse all →