XCSSET v40 Targets macOS Developers via Poisoned Xcode Projects
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
XCSSET v40 has emerged as a significant threat to macOS developers, utilizing poisoned Xcode projects to compromise local builds and execute supply chain attacks. This version can hijack Chrome and Trojanize Telegram while operating primarily from memory, employing aggressive polymorphism to evade detection. The malware can steal cookies and execute commands via the Chrome DevTools Protocol, posing a risk not only to individual developers but also to organizations that rely on their code. The resurgence of XCSSET comes after several months of inactivity, indicating a potential shift in tactics by its operators. Developers are urged to remain vigilant as the malware can spread through affected projects, amplifying its impact across the ecosystem. Current status indicates that the malware is active and poses a high risk to macOS systems.
Key Points: • XCSSET v40 infects Xcode projects to compromise macOS development environments. • The malware can hijack Chrome and Trojanize Telegram, operating from memory. • Developers and organizations using affected codebases are at significant risk.