ThreatCluster

XCSSET v40 Targets macOS Developers via Poisoned Xcode Projects

First seen 3 Aug 2026, 14:53 UTC GbhackersCybersecuritynews 84% similarity 70

Article Content

Browse articles
ThreatCluster

XCSSET v40 has emerged as a significant threat to macOS developers, utilizing poisoned Xcode projects to compromise local builds and execute supply chain attacks. This version can hijack Chrome and Trojanize Telegram while operating primarily from memory, employing aggressive polymorphism to evade detection. The malware can steal cookies and execute commands via the Chrome DevTools Protocol, posing a risk not only to individual developers but also to organizations that rely on their code. The resurgence of XCSSET comes after several months of inactivity, indicating a potential shift in tactics by its operators. Developers are urged to remain vigilant as the malware can spread through affected projects, amplifying its impact across the ecosystem. Current status indicates that the malware is active and poses a high risk to macOS systems.

Key Points: • XCSSET v40 infects Xcode projects to compromise macOS development environments. • The malware can hijack Chrome and Trojanize Telegram, operating from memory. • Developers and organizations using affected codebases are at significant risk.

ThreatCluster AI How this analysis works

Timeline

2026-08-03
XCSSET v40 released
The latest version of XCSSET resurfaces with enhanced capabilities targeting macOS developers through poisoned Xcode projects.
Gbhackers
2026-08-03
Malware exploits Chrome DevTools Protocol
XCSSET v40 can steal cookies and execute commands, increasing the risk for developers and organizations.
Cybersecuritynews

Community

Browse all →

Tracked Entities in This Story