Intelligence
highMalwareActive

XCSSET v40 targets macOS developers with fileless modules and stronger evasion

Unit 42 observed XCSSET v40 spreading through infected Xcode projects from April 2026, with a second wave and new modules in May. Activity focused on developers in South Asia and added Chrome-hijacking and Telegram-trojanising capabilities.

S
Sebastion

Affected

XcodemacOS developersApple development ecosystem

Unit 42 began tracking XCSSET v40 in mid-April 2026 and observed a second wave in early May that introduced an expanded module set. The campaign showed a heightened focus on developers in South Asia, consistent with the regional focus reported when XCSSET was first documented in 2020.

The malware spreads through infected Xcode projects and vulnerable Git repositories. Infection begins when a developer builds an affected project locally. Its staged chain fingerprints the host, retrieves modules and loads the core logic into memory before deleting installation files. Unit 42 reported multi-layered encryption, polymorphic payload generation, fileless persistence, dynamic in-memory execution and attempts to weaken host security controls.

Researchers identified 17 modules, including two new components. A Chrome-hijacking backdoor wraps the legitimate browser, enables the Chrome DevTools Protocol and injects remote JavaScript into browser sessions; it can steal data, manipulate cryptocurrency activity and provide a route to execute host commands. A Telegram trojanizer, first observed in the May wave, replaces the legitimate Telegram application with a C2-supplied, ad hoc-signed version.

The wider module set supports capabilities including keylogging, clipboard and browser hijacking, credential theft and data exfiltration. XCSSET can also infect existing Xcode projects on a compromised system, extending its supply-chain reach.

Development teams should inspect Xcode projects and repositories for Unit 42's published indicators, monitor unusual browser wrappers and application replacement, and prioritise investigation of unexpected in-memory activity on macOS development systems.