Skip to content
Tech News
← Back to articles

New XCSSET variant targets macOS devs via compromised Xcode projects

read original more articles
Why This Matters

The resurgence of the XCSSET malware targeting macOS developers through compromised Xcode projects underscores the increasing sophistication of supply chain attacks in the tech industry. This highlights the need for heightened security measures among developers and organizations to prevent widespread infections and data breaches. Consumers and businesses alike must remain vigilant as malware evolves to exploit trusted development tools and repositories.

Key Takeaways

A new version of the XCSSET malware is targeting thousands of macOS users through compromised Xcode projects and GitHub repositories.

Xcode is the official software development kit (SDK) for creating, testing, and publishing software for all Apple's platforms.

After months of inactivity, XCSSET has resurfaced with an updated version, v40, that features enhanced evasion techniques and introduces two new components, researchers have found.

Researchers at Palo Alto Networks' Unit 42, who analyzed the infection chain, say the threat actor spreads the malware by compromising vulnerable Git repositories and injecting a downloader script into benign files within Xcode projects.

Developers downloading the compromised projects become infected upon building them, allowing XCSSET to compromise every other Xcode project on the system and propagate further through shared source code.

Infected Xcode project

Source: Unit 42

Unit 42 researchers observed XCSSET version 40 used in two distinct attack waves in mid-April and in early May.

XCSSET has targeted macOS systems since at least 2021 and has, in some cases, exploited zero-day vulnerabilities in its attacks.

In September 2025, Microsoft warned of an XCSSET campaign that used compromised Xcode projects as a distribution mechanism. The company had also previously identified a variant of the malware that introduced cryptocurrency-theft capabilities.

... continue reading