{"id":824,"date":"2026-08-19T08:56:02","date_gmt":"2026-08-19T03:26:02","guid":{"rendered":"https:\/\/www.hexnode.com\/threat-watch\/?p=824"},"modified":"2026-08-19T08:56:58","modified_gmt":"2026-08-19T03:26:58","slug":"xcsset-v40-macos-developer-endpoint-security","status":"publish","type":"post","link":"https:\/\/www.hexnode.com\/threat-watch\/xcsset-v40-macos-developer-endpoint-security\/","title":{"rendered":"XCSSET v40 Targets macOS Developers: Securing the Software Supply Chain"},"content":{"rendered":"<p>A newly observed XCSSET campaign underscores how software supply-chain attacks continue to evolve beyond package repositories and dependency poisoning. By compromising legitimate Xcode projects hosted in Git repositories, attackers can infect macOS developer workstations during the normal build process, turning trusted development workflows into an initial access vector.<\/p>\n<p>For enterprise security teams, the risk extends well beyond a single compromised endpoint. Developer systems typically have privileged access to source code, signing certificates, cloud environments, CI\/CD pipelines, SSH keys, and browser-based authentication sessions. A successful compromise can therefore enable credential theft, lateral movement, and broader software supply-chain exposure.<\/p>\n<p>The latest XCSSET variant also introduces new capabilities for browser hijacking, credential theft, and persistence, highlighting the need for organizations to strengthen developer endpoint security alongside secure software development practices. For IT and security leaders, this incident reinforces the importance of combining endpoint hardening, continuous threat detection, and repository security controls to reduce the attack surface of macOS development environments.<\/p>\n<h2>How the XCSSET Attack Works<\/h2>\n<p>The infection chain begins when a developer builds a compromised Xcode project. A malicious run-script phase executes in the background, contacts attacker-controlled infrastructure, fingerprints the host, and retrieves additional payloads through a four-stage delivery process. The final orchestrator then loads task-specific modules primarily into memory, reducing the malware\u2019s on-disk footprint.<\/p>\n<p>Unit 42 identified 17 modules in XCSSET v40, covering functions such as:<\/p>\n<ul>\n<li>Credential and browser-data theft<\/li>\n<li>Keystroke and clipboard monitoring<\/li>\n<li>Xcode project and Git hook infection<\/li>\n<li>Data discovery and exfiltration<\/li>\n<li>Browser hijacking and persistence<\/li>\n<li>Virtual machine detection and defense evasion<\/li>\n<\/ul>\n<p>The new Chrome hijacking backdoor wraps the legitimate Chrome binary in a malicious launcher and starts the browser with the Chrome DevTools Protocol (CDP) exposed on a predefined local port. The attacker then uses a secondary binary to connect through the exposed CDP port and retrieve malicious JavaScript over a persistent WebSocket connection, injecting the attacker-controlled code into browser sessions.<\/p>\n<p>This access allows the malware to intercept credentials, cookies, API tokens, and password-manager autofill data. It can also manipulate MetaMask interactions, alter cryptocurrency wallet addresses or decentralized application transactions, and execute host-level commands through a fileless reverse shell routed via the active CDP connection.<\/p>\n<h3>Advanced Evasion and Persistence Techniques<\/h3>\n<p>XCSSET v40 also introduces a Telegram trojanizer. The module deletes the legitimate Telegram Desktop application, installs an attacker-supplied replacement, applies an ad hoc code signature, and terminates the original process so that the user relaunches the trojanized version.<\/p>\n<p>Its evasion architecture combines several techniques:<\/p>\n<ul>\n<li>Frequent recompilation of loader binaries to rotate file hashes<\/li>\n<li>AES-256-CBC encryption with per-build keys and randomized initialization vectors<\/li>\n<li>Separate encryption keys for inbound and outbound communications<\/li>\n<li>Per-module string encoding and identifier substitution<\/li>\n<li>Memory-resident module execution and cleanup of staging files<\/li>\n<li>Attempts to disrupt software updates, XProtect signatures, Apple telemetry, and TCC permission decisions<\/li>\n<\/ul>\n<p>These controls make static indicators less reliable and shift detection requirements toward behavioral telemetry, including anomalous build scripts, unusual AppleScript execution, unauthorized browser launch arguments, ad hoc-signed application replacement, and suspicious modifications to macOS preference domains.<br \/>\n<div class=\"next_blog\"><div class=\"post-next\"><div class=\"hex_blog_box_parent\"><div class=\"blog_warp_next\"><div class=\"next_blog_thumb\" style=\"background-image:url(https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/digital-employee-experience-strategy-1024x535-1.webp?format=webp)\"><\/div><div class=\"next_post_content\"><div class=\"center_box\"><h4>3 Pillars of a Digital Employee Experience Strategy<\/h4><p>Fix digital friction with a DEX strategy built on visibility, proactive remediation, and feedback.<\/p><\/div><\/div><\/div><a class=\"hex_blog_box_link hn-cta__blogs--blog-box\" href=\"https:\/\/www.hexnode.com\/blogs\/3-pillars-of-a-digital-employee-experience-strategy\/\" aria-label=\"3 Pillars of a Digital Employee Experience Strategy\"><\/a><\/div><\/div><\/div><\/p>\n<h2>The Hexnode Solution<\/h2>\n<p>Mitigating threats like XCSSET v40 requires more than signature-based detection. Organizations need layered controls that reduce the attack surface of developer workstations, continuously validate endpoint posture, and detect malicious behavior that bypasses preventive defenses.<\/p>\n<p><a href=\"https:\/\/www.hexnode.com\/\" rel=\"noopener\">Hexnode UEM<\/a> helps organizations establish and maintain a secure baseline for macOS developer endpoints by enabling administrators to:<\/p>\n<ul>\n<li>Enforce macOS security configurations across managed devices.<\/li>\n<li>Maintain software inventory to improve visibility into installed applications and identify unauthorized software.<\/li>\n<li>Drive OS update compliance to ensure developer systems receive the latest macOS security patches and protections.<\/li>\n<li>Restrict application execution using approved application policies, reducing the risk of untrusted software running on managed devices.<\/li>\n<li>Standardize secure developer workstation baselines through centralized policy management and ongoing compliance enforcement.<\/li>\n<\/ul>\n<p>On the detection side, <a href=\"https:\/\/www.hexnode.com\/xdr\/\" rel=\"noopener\">Hexnode XDR<\/a> provides security teams with centralized visibility and threat detection capabilities across endpoints, helping them investigate and respond to potential security incidents. Core XDR capabilities include:<\/p>\n<ul>\n<li>Continuous endpoint monitoring and collection of security-relevant telemetry.<\/li>\n<li>Detection and correlation of suspicious activity to surface potential threats.<\/li>\n<li>Centralized visibility into endpoint security events and alerts.<\/li>\n<li>Investigation capabilities that help security teams analyze detected threats and understand their context.<\/li>\n<li>Response capabilities that enable teams to take action against identified threats and reduce potential impact.<\/li>\n<\/ul>\n<p>Organizations can further reduce risk by enforcing identity-aware access to critical development resources. Restricting access to source code repositories, build infrastructure, and CI\/CD platforms to compliant, managed devices helps ensure that even if a developer&#8217;s credentials are compromised, access to sensitive systems remains governed by device trust and security posture.<br \/>\n<section id='resource-single'>\n                    <div class='resource-box'>\n                        <div class='resource-box__image-section'>\n                            <div class='resource-box__image-wrap'>\n                                <img decoding=\"async\" src=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Thumbnail-For-XDR-Intro-Deck.webp?format=webp\" class=\"resource-box__image\" alt=\"Thumbnail-For-XDR-Intro-Deck\" loading=\"lazy\" srcset=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Thumbnail-For-XDR-Intro-Deck.webp?format=webp 1796w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Thumbnail-For-XDR-Intro-Deck-300x168.webp?format=webp 300w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Thumbnail-For-XDR-Intro-Deck-1024x575.webp?format=webp 1024w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Thumbnail-For-XDR-Intro-Deck-768x431.webp?format=webp 768w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Thumbnail-For-XDR-Intro-Deck-1536x862.webp?format=webp 1536w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Thumbnail-For-XDR-Intro-Deck-178x100.webp?format=webp 178w\" sizes=\"auto, (max-width: 1796px) 100vw, 1796px\" title=\"Thumbnail-For-XDR-Intro-Deck\" \/>\n                            <\/div>\n                        <\/div>\n                        <div class='resource-box__content-section'>\n                            <h5 class='resource-box__content-subheading'>\n                            Feature Resource \n                            <\/h5>\n                            <h4 class='resource-box__content-heading'>\n                            Introduction to Hexnode XDR\n                            <\/h4>\n                            <p class='resource-box__contents'>\n                            Learn how to close the security loop by combining proactive device management with advanced threat detection and response.\n                            <\/p>\n                            <a class='resource-box__content-link hn-cta__blogs--resource-box' href='https:\/\/www.hexnode.com\/resources\/introduction-to-hexnode-xdr\/'>\n                            Get Introduction to Hexnode XDR\n                            <svg xmlns='http:\/\/www.w3.org\/2000\/svg' width='20' height='20' viewBox='0 0 20 20'>\n                            <g id='arrow' transform='translate(-309 -191)' opacity='0'>\n                                <rect id='base' width='20' height='20' transform='translate(309 191)' fill='none'\/>\n                                <path id='arrow-2' data-name='arrow' d='M13.093.5,6.8,6.8.5.5' transform='translate(315 207.594) rotate(-90)' fill='none' stroke='#0549d1' stroke-linecap='round' stroke-linejoin='round' stroke-width='1.2'\/>\n                            <\/g>\n                            <\/svg>\n\n                            <\/a>\n                        <\/div>\n                    <\/div>\n                <\/section><\/p>\n<h2>Conclusion<\/h2>\n<p>XCSSET v40 is a reminder that developer workstations are a critical component of the software supply chain. As attackers increasingly target trusted development environments instead of exploiting traditional perimeter defenses, organizations must treat macOS developer endpoints as high-value assets that require the same level of protection as production infrastructure.<\/p>\n<p>Reducing the risk of similar attacks requires a defense-in-depth strategy that combines endpoint hardening, continuous threat detection, secure access controls, and software supply-chain security. Enterprises should prioritize:<\/p>\n<ul>\n<li>Hardening macOS developer endpoints with standardized security baselines and timely OS updates.<\/li>\n<li>Verifying the provenance of Xcode projects and Git repositories before building or executing code.<\/li>\n<li>Monitoring build activity and endpoint behavior for indicators of malicious scripts, persistence, and credential theft.<\/li>\n<li>Protecting developer identities and privileged access by enforcing device compliance and identity-aware access to source code repositories and CI\/CD systems.<\/li>\n<\/ul>\n<p>As attacks like XCSSET continue to evolve, organizations that combine strong endpoint security, behavioral detection, and identity-based access controls will be better positioned to limit compromise, contain malicious activity, and protect their software development ecosystem.<br \/>\n<div class=\"signup_box\"><div class=\"signup_wrap_img\"><div class=\"signup-bg\" style=\"background-image:url(https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode-MDM-free-trial.jpg?format=webp)\"><\/div><\/div><div class=\"signup_wrap\"><h5>Try Hexnode free for 14 days<\/h5><p>Secure every endpoint. Simplify IT. See how Hexnode strengthens your enterprise security posture.<\/p><a href=\"https:\/\/www.hexnode.com\/mobile-device-management\/cloud\/signup\/\" class=\"hn-cta__blogs--signup-stripe\" target=\"_blank\"> Sign Up Today<\/a><\/div><\/div><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A newly observed XCSSET campaign underscores how software supply-chain attacks continue to evolve beyond package&#8230;<\/p>\n","protected":false},"author":8,"featured_media":825,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[13,17],"class_list":["post-824","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-identity-abuse","category-macos","product_category-extended-detection-and-response","tab_group-malware-and-ransomware"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>XCSSET v40 Targets macOS Developers: Securing the Software Supply Chain<\/title>\n<meta name=\"description\" content=\"XCSSET v40 targets macOS developers through compromised Xcode projects. Learn endpoint, XDR, and UEM defense steps.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.hexnode.com\/threat-watch\/xcsset-v40-macos-developer-endpoint-security\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"XCSSET v40 Targets macOS Developers: Securing the Software Supply Chain\" \/>\n<meta property=\"og:description\" content=\"XCSSET v40 targets macOS developers through compromised Xcode projects. Learn endpoint, XDR, and UEM defense steps.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.hexnode.com\/threat-watch\/xcsset-v40-macos-developer-endpoint-security\/\" \/>\n<meta property=\"og:site_name\" content=\"Hexnode Threat Watch\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Hexnode\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-08-19T03:26:02+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-19T03:26:58+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/XCSSET-v40-1024x535-1.webp?format=webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1024\" \/>\n\t<meta property=\"og:image:height\" content=\"535\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/webp\" \/>\n<meta name=\"author\" content=\"Alanna River\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:site\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Alanna River\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":[\"Article\",\"BlogPosting\"],\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/xcsset-v40-macos-developer-endpoint-security\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/xcsset-v40-macos-developer-endpoint-security\\\/\"},\"author\":{\"name\":\"Alanna River\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/c2ed050402be36f7ece23a9b07bc9e64\"},\"headline\":\"XCSSET v40 Targets macOS Developers: Securing the Software Supply Chain\",\"datePublished\":\"2026-08-19T03:26:02+00:00\",\"dateModified\":\"2026-08-19T03:26:58+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/xcsset-v40-macos-developer-endpoint-security\\\/\"},\"wordCount\":942,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/xcsset-v40-macos-developer-endpoint-security\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/XCSSET-v40-1024x535-1.webp?format=webp\",\"articleSection\":[\"Identity Abuse\",\"macOS\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/xcsset-v40-macos-developer-endpoint-security\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/xcsset-v40-macos-developer-endpoint-security\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/xcsset-v40-macos-developer-endpoint-security\\\/\",\"name\":\"XCSSET v40 Targets macOS Developers: Securing the Software Supply Chain\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/xcsset-v40-macos-developer-endpoint-security\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/xcsset-v40-macos-developer-endpoint-security\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/XCSSET-v40-1024x535-1.webp?format=webp\",\"datePublished\":\"2026-08-19T03:26:02+00:00\",\"dateModified\":\"2026-08-19T03:26:58+00:00\",\"description\":\"XCSSET v40 targets macOS developers through compromised Xcode projects. Learn endpoint, XDR, and UEM defense steps.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/xcsset-v40-macos-developer-endpoint-security\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/xcsset-v40-macos-developer-endpoint-security\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/xcsset-v40-macos-developer-endpoint-security\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/XCSSET-v40-1024x535-1.webp?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/XCSSET-v40-1024x535-1.webp?format=webp\",\"width\":1024,\"height\":535,\"caption\":\"XCSSET-v40\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/xcsset-v40-macos-developer-endpoint-security\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"XCSSET v40 Targets macOS Developers: Securing the Software Supply Chain\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"name\":\"Hexnode Threat Watch\",\"description\":\"Latest cyber threats, smarter enterprise response.\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"alternateName\":\"Threat Watch\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\",\"name\":\"Hexnode\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"width\":100,\"height\":100,\"caption\":\"Hexnode\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/Hexnode\\\/\",\"https:\\\/\\\/x.com\\\/thehexnode\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/hexnode\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/c2ed050402be36f7ece23a9b07bc9e64\",\"name\":\"Alanna River\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/1d91e52e837001aa3e782febef8d4339b30257abee06ef86933aebc57aa48248?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/1d91e52e837001aa3e782febef8d4339b30257abee06ef86933aebc57aa48248?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/1d91e52e837001aa3e782febef8d4339b30257abee06ef86933aebc57aa48248?s=96&d=mm&r=g\",\"caption\":\"Alanna River\"},\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/author\\\/alanna-river\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"XCSSET v40 Targets macOS Developers: Securing the Software Supply Chain","description":"XCSSET v40 targets macOS developers through compromised Xcode projects. Learn endpoint, XDR, and UEM defense steps.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.hexnode.com\/threat-watch\/xcsset-v40-macos-developer-endpoint-security\/","og_locale":"en_US","og_type":"article","og_title":"XCSSET v40 Targets macOS Developers: Securing the Software Supply Chain","og_description":"XCSSET v40 targets macOS developers through compromised Xcode projects. Learn endpoint, XDR, and UEM defense steps.","og_url":"https:\/\/www.hexnode.com\/threat-watch\/xcsset-v40-macos-developer-endpoint-security\/","og_site_name":"Hexnode Threat Watch","article_publisher":"https:\/\/www.facebook.com\/Hexnode\/","article_published_time":"2026-08-19T03:26:02+00:00","article_modified_time":"2026-08-19T03:26:58+00:00","og_image":[{"width":1024,"height":535,"url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/XCSSET-v40-1024x535-1.webp?format=webp","type":"image\/webp"}],"author":"Alanna River","twitter_card":"summary_large_image","twitter_creator":"@thehexnode","twitter_site":"@thehexnode","twitter_misc":{"Written by":"Alanna River","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":["Article","BlogPosting"],"@id":"https:\/\/www.hexnode.com\/threat-watch\/xcsset-v40-macos-developer-endpoint-security\/#article","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/xcsset-v40-macos-developer-endpoint-security\/"},"author":{"name":"Alanna River","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/c2ed050402be36f7ece23a9b07bc9e64"},"headline":"XCSSET v40 Targets macOS Developers: Securing the Software Supply Chain","datePublished":"2026-08-19T03:26:02+00:00","dateModified":"2026-08-19T03:26:58+00:00","mainEntityOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/xcsset-v40-macos-developer-endpoint-security\/"},"wordCount":942,"commentCount":0,"publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/xcsset-v40-macos-developer-endpoint-security\/#primaryimage"},"thumbnailUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/XCSSET-v40-1024x535-1.webp?format=webp","articleSection":["Identity Abuse","macOS"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.hexnode.com\/threat-watch\/xcsset-v40-macos-developer-endpoint-security\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.hexnode.com\/threat-watch\/xcsset-v40-macos-developer-endpoint-security\/","url":"https:\/\/www.hexnode.com\/threat-watch\/xcsset-v40-macos-developer-endpoint-security\/","name":"XCSSET v40 Targets macOS Developers: Securing the Software Supply Chain","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/xcsset-v40-macos-developer-endpoint-security\/#primaryimage"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/xcsset-v40-macos-developer-endpoint-security\/#primaryimage"},"thumbnailUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/XCSSET-v40-1024x535-1.webp?format=webp","datePublished":"2026-08-19T03:26:02+00:00","dateModified":"2026-08-19T03:26:58+00:00","description":"XCSSET v40 targets macOS developers through compromised Xcode projects. Learn endpoint, XDR, and UEM defense steps.","breadcrumb":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/xcsset-v40-macos-developer-endpoint-security\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.hexnode.com\/threat-watch\/xcsset-v40-macos-developer-endpoint-security\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/xcsset-v40-macos-developer-endpoint-security\/#primaryimage","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/XCSSET-v40-1024x535-1.webp?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/XCSSET-v40-1024x535-1.webp?format=webp","width":1024,"height":535,"caption":"XCSSET-v40"},{"@type":"BreadcrumbList","@id":"https:\/\/www.hexnode.com\/threat-watch\/xcsset-v40-macos-developer-endpoint-security\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.hexnode.com\/threat-watch\/"},{"@type":"ListItem","position":2,"name":"XCSSET v40 Targets macOS Developers: Securing the Software Supply Chain"}]},{"@type":"WebSite","@id":"https:\/\/www.hexnode.com\/threat-watch\/#website","url":"https:\/\/www.hexnode.com\/threat-watch\/","name":"Hexnode Threat Watch","description":"Latest cyber threats, smarter enterprise response.","publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"alternateName":"Threat Watch","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.hexnode.com\/threat-watch\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization","name":"Hexnode","url":"https:\/\/www.hexnode.com\/threat-watch\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","width":100,"height":100,"caption":"Hexnode"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Hexnode\/","https:\/\/x.com\/thehexnode","https:\/\/www.linkedin.com\/company\/hexnode"]},{"@type":"Person","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/c2ed050402be36f7ece23a9b07bc9e64","name":"Alanna River","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/1d91e52e837001aa3e782febef8d4339b30257abee06ef86933aebc57aa48248?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/1d91e52e837001aa3e782febef8d4339b30257abee06ef86933aebc57aa48248?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/1d91e52e837001aa3e782febef8d4339b30257abee06ef86933aebc57aa48248?s=96&d=mm&r=g","caption":"Alanna River"},"url":"https:\/\/www.hexnode.com\/threat-watch\/author\/alanna-river\/"}]}},"_links":{"self":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/824","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/comments?post=824"}],"version-history":[{"count":2,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/824\/revisions"}],"predecessor-version":[{"id":829,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/824\/revisions\/829"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media\/825"}],"wp:attachment":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media?parent=824"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/categories?post=824"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}