BleepingComputer reported that a new XCSSET malware variant is targeting macOS developers through compromised Xcode projects and GitHub repositories.
Unit 42 said the threat actor compromises vulnerable Git repositories and injects a downloader script into benign files inside Xcode projects.
Developers become infected when they build compromised projects, and the malware can then compromise other Xcode projects on the same system to propagate through shared source code.
The new XCSSET version 40 uses a four-stage infection chain before deploying 17 modules for credential theft, keystroke logging, clipboard manipulation, browser hijacking, and data exfiltration.
New modules include a Chrome hijacker and a Telegram trojanizer.
The Chrome hijacker wraps Chrome in a malicious launcher, enables Chrome DevTools Protocol on a local port, fetches JavaScript from attacker infrastructure, intercepts credentials and cookies, manipulates MetaMask transactions, and supports fileless reverse shell behavior.
The malware attempts to disable macOS security components including XProtect, MRT, TCC, and Rapid Security Response, terminates Apple’s CloudTelemetryService, and prevents XProtect signature updates.
A newly observed XCSSET campaign underscores how software supply-chain attacks continue to evolve beyond package repositories and dependency poisoning. By compromising legitimate Xcode projects hosted in Git repositories, attackers can infect macOS developer workstations during the normal build process, turning trusted development workflows into an initial access vector.
For enterprise security teams, the risk extends well beyond a single compromised endpoint. Developer systems typically have privileged access to source code, signing certificates, cloud environments, CI/CD pipelines, SSH keys, and browser-based authentication sessions. A successful compromise can therefore enable credential theft, lateral movement, and broader software supply-chain exposure.
The latest XCSSET variant also introduces new capabilities for browser hijacking, credential theft, and persistence, highlighting the need for organizations to strengthen developer endpoint security alongside secure software development practices. For IT and security leaders, this incident reinforces the importance of combining endpoint hardening, continuous threat detection, and repository security controls to reduce the attack surface of macOS development environments.
The infection chain begins when a developer builds a compromised Xcode project. A malicious run-script phase executes in the background, contacts attacker-controlled infrastructure, fingerprints the host, and retrieves additional payloads through a four-stage delivery process. The final orchestrator then loads task-specific modules primarily into memory, reducing the malware’s on-disk footprint.
Unit 42 identified 17 modules in XCSSET v40, covering functions such as:
Credential and browser-data theft
Keystroke and clipboard monitoring
Xcode project and Git hook infection
Data discovery and exfiltration
Browser hijacking and persistence
Virtual machine detection and defense evasion
The new Chrome hijacking backdoor wraps the legitimate Chrome binary in a malicious launcher and starts the browser with the Chrome DevTools Protocol (CDP) exposed on a predefined local port. The attacker then uses a secondary binary to connect through the exposed CDP port and retrieve malicious JavaScript over a persistent WebSocket connection, injecting the attacker-controlled code into browser sessions.
This access allows the malware to intercept credentials, cookies, API tokens, and password-manager autofill data. It can also manipulate MetaMask interactions, alter cryptocurrency wallet addresses or decentralized application transactions, and execute host-level commands through a fileless reverse shell routed via the active CDP connection.
Advanced Evasion and Persistence Techniques
XCSSET v40 also introduces a Telegram trojanizer. The module deletes the legitimate Telegram Desktop application, installs an attacker-supplied replacement, applies an ad hoc code signature, and terminates the original process so that the user relaunches the trojanized version.
Its evasion architecture combines several techniques:
Frequent recompilation of loader binaries to rotate file hashes
AES-256-CBC encryption with per-build keys and randomized initialization vectors
Separate encryption keys for inbound and outbound communications
Per-module string encoding and identifier substitution
Memory-resident module execution and cleanup of staging files
Attempts to disrupt software updates, XProtect signatures, Apple telemetry, and TCC permission decisions
These controls make static indicators less reliable and shift detection requirements toward behavioral telemetry, including anomalous build scripts, unusual AppleScript execution, unauthorized browser launch arguments, ad hoc-signed application replacement, and suspicious modifications to macOS preference domains.
3 Pillars of a Digital Employee Experience Strategy
Fix digital friction with a DEX strategy built on visibility, proactive remediation, and feedback.
The Hexnode Solution
Mitigating threats like XCSSET v40 requires more than signature-based detection. Organizations need layered controls that reduce the attack surface of developer workstations, continuously validate endpoint posture, and detect malicious behavior that bypasses preventive defenses.
Hexnode UEM helps organizations establish and maintain a secure baseline for macOS developer endpoints by enabling administrators to:
Enforce macOS security configurations across managed devices.
Maintain software inventory to improve visibility into installed applications and identify unauthorized software.
Drive OS update compliance to ensure developer systems receive the latest macOS security patches and protections.
Restrict application execution using approved application policies, reducing the risk of untrusted software running on managed devices.
Standardize secure developer workstation baselines through centralized policy management and ongoing compliance enforcement.
On the detection side, Hexnode XDR provides security teams with centralized visibility and threat detection capabilities across endpoints, helping them investigate and respond to potential security incidents. Core XDR capabilities include:
Continuous endpoint monitoring and collection of security-relevant telemetry.
Detection and correlation of suspicious activity to surface potential threats.
Centralized visibility into endpoint security events and alerts.
Investigation capabilities that help security teams analyze detected threats and understand their context.
Response capabilities that enable teams to take action against identified threats and reduce potential impact.
Organizations can further reduce risk by enforcing identity-aware access to critical development resources. Restricting access to source code repositories, build infrastructure, and CI/CD platforms to compliant, managed devices helps ensure that even if a developer’s credentials are compromised, access to sensitive systems remains governed by device trust and security posture.
Feature Resource
Introduction to Hexnode XDR
Learn how to close the security loop by combining proactive device management with advanced threat detection and response.
XCSSET v40 is a reminder that developer workstations are a critical component of the software supply chain. As attackers increasingly target trusted development environments instead of exploiting traditional perimeter defenses, organizations must treat macOS developer endpoints as high-value assets that require the same level of protection as production infrastructure.
Reducing the risk of similar attacks requires a defense-in-depth strategy that combines endpoint hardening, continuous threat detection, secure access controls, and software supply-chain security. Enterprises should prioritize:
Hardening macOS developer endpoints with standardized security baselines and timely OS updates.
Verifying the provenance of Xcode projects and Git repositories before building or executing code.
Monitoring build activity and endpoint behavior for indicators of malicious scripts, persistence, and credential theft.
Protecting developer identities and privileged access by enforcing device compliance and identity-aware access to source code repositories and CI/CD systems.
As attacks like XCSSET continue to evolve, organizations that combine strong endpoint security, behavioral detection, and identity-based access controls will be better positioned to limit compromise, contain malicious activity, and protect their software development ecosystem.
Try Hexnode free for 14 days
Secure every endpoint. Simplify IT. See how Hexnode strengthens your enterprise security posture.
I’m a technical content writer at Hexnode who loves simplifying tech. I break down complex ideas, remove the fluff, and help readers clearly understand our product for what it actually is: simple, reliable, and built to solve real problems.