Bleepingcomputer XCSSET v40 Targets macOS Developers via Poisoned Xcode Projects
Article Content
- •XCSSET v40 infects Xcode projects to compromise macOS development environments.
- •The malware can hijack Chrome and Trojanize Telegram, operating from memory.
- •Developers and organizations using affected codebases are at significant risk.
XCSSET v40 has emerged as a significant threat to macOS developers, utilizing poisoned Xcode projects to compromise local builds and execute supply chain attacks. This version can hijack Chrome and Trojanize Telegram while operating primarily from memory, employing aggressive polymorphism to evade detection. The malware can steal cookies and execute commands via the Chrome DevTools Protocol, posing a risk not only to individual developers but also to organizations that rely on their code. The resurgence of XCSSET comes after several months of inactivity, indicating a potential shift in tactics by its operators. Developers are urged to remain vigilant as the malware can spread through affected projects, amplifying its impact across the ecosystem. Current status indicates that the malware is active and poses a high risk to macOS systems.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (5)
Following this threat?
Track Xcsset in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
XCSSET Malware Evolves with Enhanced Obfuscation and Persistence Techniques The XCSSET malware has released a new variant, v40, targeting macOS systems and specifically infecting Xcode projects. This version employs advanced obfuscation techniques, including polymorphic payload generation and fileless persistence, significantly reducing its digital footprint. The malware has spread through…
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…