Skip to content
XCSSET v40 Targets macOS Developers via Poisoned Xcode Projects

XCSSET v40 Targets macOS Developers via Poisoned Xcode Projects

First seen 3 Aug 2026, 14:53 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster August 4, 2026 at 14:52 UTC
  • XCSSET v40 infects Xcode projects to compromise macOS development environments.
  • The malware can hijack Chrome and Trojanize Telegram, operating from memory.
  • Developers and organizations using affected codebases are at significant risk.

XCSSET v40 has emerged as a significant threat to macOS developers, utilizing poisoned Xcode projects to compromise local builds and execute supply chain attacks. This version can hijack Chrome and Trojanize Telegram while operating primarily from memory, employing aggressive polymorphism to evade detection. The malware can steal cookies and execute commands via the Chrome DevTools Protocol, posing a risk not only to individual developers but also to organizations that rely on their code. The resurgence of XCSSET comes after several months of inactivity, indicating a potential shift in tactics by its operators. Developers are urged to remain vigilant as the malware can spread through affected projects, amplifying its impact across the ecosystem. Current status indicates that the malware is active and poses a high risk to macOS systems.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 48d ago How this analysis works

Timeline

2026-08-03
XCSSET v40 released
The latest version of XCSSET resurfaces with enhanced capabilities targeting macOS developers through poisoned Xcode projects.
Gbhackers
2026-08-03
Malware exploits Chrome DevTools Protocol
XCSSET v40 can steal cookies and execute commands, increasing the risk for developers and organizations.
Cybersecuritynews

More articles in this cluster (5)

Following this threat?

Track Xcsset in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed