Threat reportMalwareTL-2026-1792

XCSSET v40: Fileless macOS Xcode-Supply-Chain Malware Adds Chrome DevTools Protocol Hijacking and Telegram Trojanization

highACTIVE

XCSSET v40: Fileless macOS Xcode-Supply-Chain Malware Adds (TL-2026-1792), also tracked as XCSSET v40, is a high-severity malware campaign, first published 2026-07-31. It has no confirmed attribution, affects Apple Xcode, maps to 32 MITRE ATT&CK techniques (T1005, T1008, T1027), and is covered by 9 detection rules and 86 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
32MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
86Indicators of compromise

Key facts for TL-2026-1792

Threat ID
TL-2026-1792
Also known as
XCSSET v40, XCSSET
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
Last reviewed
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
technology, software development
Target regions
South Asia, india, Global
Detection rules
9
Indicators of compromise
86

Malware and tooling in XCSSET v40: Fileless macOS Xcode-Supply-Chain Malware Adds

Malware and tooling: XCSSET, XCSSET v40, XCSSET custom HTTP(S) C2, chrome_remote, tdesktop

How XCSSET v40: Fileless macOS Xcode-Supply-Chain Malware Adds works

Unit 42 documents XCSSET version 40, a macOS malware family propagating via infected Xcode projects on GitHub that now hides its core logic in memory using polymorphic payload generation, fileless persistence via the macOS `defaults` system, and a multi-layered cipher scheme. v40 adds a Chrome DevTools Protocol (CDP) hijacking backdoor and a Telegram Desktop trojanizer module, and actively impairs XProtect, TCC, and Apple's software-update defenses while primarily targeting developers across South Asia.

XCSSET is a modular macOS malware family, first documented by Trend Micro in August 2020, that propagates by injecting malicious Run Script build phases and git pre-commit hooks into Xcode projects hosted on GitHub and other developer repositories. When an infected project is built, the injected script triggers a four-stage execution chain: (1) an initial loader with an encoded payload runs during the Xcode build phase; (2) a host-reconnaissance step collects OS type, username, and serial number via curl requests to the C2; (3) a staging step downloads loader binaries, wraps them in temporary AppleScript, executes them in memory via osascript, and deletes the disk artifacts; and (4) a core 'boot' orchestrator module retrieves and runs up to 17 additional functional modules entirely in memory from C2 infrastructure. Propagation continues through recursive traversal of user directories to infect zip-archived Xcode projects and through git pre-commit hook injection, alongside classic trojanized-application distribution.

Version 40 (deployed from early April 2026, with a second wave in May 2026 after months of dormancy) is a substantial architectural upgrade over the intermediate variants Microsoft documented in March and September 2025. It introduces a novel fileless persistence mechanism that abuses the macOS `defaults` preference system (functionally analogous to the Windows Registry) to store Base64-encoded staging payloads under randomized preference keys (e.g. `mpirv_eahpi_apm`); when a trojanized application later launches, a single command retrieves, decodes, and re-executes the payload, tagging the resulting session with a source-identification (SRC) parameter. Evasion is layered at both the binary and network levels: the loader binary is recompiled on the C2 server every few hours (eight distinct SHA hashes were observed within 24 hours), in-memory modules are encrypted with AES-256-CBC using per-build keys and randomized IVs so identical modules sent seconds apart yield different ciphertext, and a dual-key architecture separates the inbound decryption key embedded in the AppleScript loader from a distinct outbound key, denying defenders who only capture network telemetry the ability to decrypt core logic. Source code itself is protected pre-compilation by a substitution cipher applied to function, module, and variable names (with no decryption mapping left on the endpoint) and a per-module keyed Caesar cipher using randomized 52-character alphabets and variable shift values for string literals; Unit 42 states it broke the identifier-substitution scheme using pattern matching assisted by an LLM, recovering the operators' original module/function names.

The two headline new modules in v40 are `chrome_remote` and `tdesktop`. `chrome_remote` wraps the legitimate Google Chrome binary in a malicious persistence script that, on every Chrome launch, restarts the XCSSET `boot` module, relaunches Chrome with the Chrome DevTools Protocol (CDP) enabled on a pre-defined local port, and drops/executes a dedicated `chrome_remote` binary that connects to that CDP port. This establishes a persistent WebSocket channel to the C2 for real-time JavaScript payload delivery and pre-page-load code injection, and overrides critical browser APIs: it hooks `window.fetch`/`XMLHttpRequest` to exfiltrate credentials and API tokens, intercepts the injected MetaMask Ethereum provider to manipulate wallet addresses and interfere with dApp transactions, and overrides password-manager autofill fields to harvest stored credentials. It also implements a fileless reverse shell by monitoring console-logging events for operator command strings, executing them via a shell handler, and returning output over the same CDP WebSocket. `tdesktop`, new as of the May 2026 wave, escalates XCSSET's historical Telegram data theft into full application trojanization: it downloads a pre-built malicious Telegram.app ZIP from the C2, kills the running legitimate Telegram process, replaces it with the ad-hoc-signed trojanized copy, and forces the victim to relaunch the compromised binary. A custom AES-encrypted configuration is pulled from a dedicated `/w?tr` C2 endpoint, decrypted to `~/.tr` with a companion state file at `~/.tr_map`, and both are periodically uploaded back to the C2 as `base_tr_file.txt` / `base_tr_map.txt`.

v40 also actively impairs macOS's own defense stack: it disables the SoftwareUpdate configuration channel to block automatic retrieval of XProtect, MRT, and TCC signature databases and to prevent access to Apple's Rapid Security Response channel; it runs a constant loop that terminates the `CloudTelemetryService` process to stop local security telemetry from reaching Apple (and thereby keep operator tooling out of future XProtect signature updates); it spawns a Perl process that acquires an exclusive file lock on the XProtect YARA-rule database (XPdb) to block signature writes to disk; and it invokes `tccutil reset AppleEvents` to wipe existing TCC decisions, then re-presents automation permission prompts disguised as System Settings or Xcode so the victim unknowingly re-grants the access XCSSET needs. A dedicated `stats` reconnaissance module performs CPU/hardware anti-VM checks before any further modules are delivered, evading automated sandbox analysis.

Targeting remains centered on software developers in the Apple ecosystem, with elevated concentration in South Asia consistent with Trend Micro's original 2020 reporting; Unit 42 states the campaign has spread through dozens of legitimate applications with thousands of active users since early April 2026. C2 infrastructure comprises roughly 40 domains registered in early 2026 across four staggered bursts and aged for months before the April attack wave to evade newly-registered-domain detection, showing a geographic pivot from 2025's `.ru`-themed CDN/tech-property lures to 2026 `.in` domains that mirror identically-named `.ru` siblings. The C2 protocol uses a small fixed set of HTTP(S) endpoints (`/d` binary download, `/a` stager retrieval, `/s` AppleScript module retrieval, `/l` status/log POST, `/u` file exfiltration POST, `/p` heartbeat, `/w?<cmd>` dynamic per-module configuration, `/e` browser-hijack event POST). Notable operator OPSEC failures let Unit 42 cluster all four identified operator IP addresses by a single shared SSL certificate thumbprint, plus reused SSH keys and a shared self-signed RDP certificate, cross-contaminating infrastructure across otherwise-separated XCSSET campaigns. No BeaconBeagle correlation matches were returned for the queried C2 IPs/domains as of 2026-07-31.

MITRE ATT&CK techniques used in TL-2026-1792

Collection

T1005 Data from Local System; T1056.001 Keylogging; T1115 Clipboard Data; T1185 Browser Session Hijacking; T1213 Data from Information Repositories

Command and Control

T1008 Fallback Channels; T1071.001 Web Protocols; T1104 Multi-Stage Channels; T1105 Ingress Tool Transfer; T1132.001 Standard Encoding; T1573.001 Symmetric Cryptography

Defense Evasion

T1027 Obfuscated Files or Information; T1036.005 Match Legitimate Resource Name or Location; T1140 Deobfuscate/Decode Files or Information; T1497.001 System Checks; T1620 Reflective Code Loading

Exfiltration

T1041 Exfiltration Over C2 Channel

Execution

T1059.002 AppleScript; T1204.002 Malicious File

Discovery

T1082 System Information Discovery; T1217 Browser Information Discovery; T1497.001 System Checks

defense-impairment

T1112 Modify Registry; T1553.002 Code Signing; T1685 Disable or Modify Tools

Initial Access

T1195.001 Compromise Software Dependencies and Development Tools

Credential Access

T1539 Steal Web Session Cookie; T1555 Credentials from Password Stores

Persistence

T1543.004 Launch Daemon; T1546.004 Unix Shell Configuration Modification; T1554 Compromise Host Software Binary

Privilege Escalation

T1543.004 Launch Daemon; T1546.004 Unix Shell Configuration Modification

Resource Development

T1583.001 Domains; T1588.002 Tool

Affected products and versions in XCSSET v40: Fileless macOS Xcode-Supply-Chain Malware Adds

  • Apple — Xcode
    Vulnerable versions: all versions supporting Run Script build phases
  • Apple — macOS
    Vulnerable versions: developer workstations running macOS, version unspecified by source
  • Google — Google Chrome (macOS)
    Vulnerable versions: all versions supporting the Chrome DevTools Protocol
  • Telegram FZ-LLC — Telegram Desktop (macOS)
    Vulnerable versions: all versions (compromised via application-binary replacement, not a code vulnerability)

Remediation for XCSSET v40: Fileless macOS Xcode-Supply-Chain Malware Adds

Patches

  • No CVE or vendor patch applies; XCSSET abuses legitimate Xcode/macOS/Chrome/Telegram functionality rather than exploiting a specific vulnerability, so mitigation is detection and hygiene, not patching
  • Confirm the SoftwareUpdate channel is not disabled by a `defaults` override, so XProtect, MRT, and TCC signature databases can continue to update

Immediate actions

  • Audit all Xcode projects (local and cloned from GitHub) for unauthorized Run Script build phases and unexpected git pre-commit/post-checkout hooks before building
  • Block the 40 identified XCSSET v40 C2 domains and 7 C2 IPs at DNS, firewall, and web proxy layers
  • Hunt across TLS telemetry for the SSL certificate thumbprint 6e480d648fa1b70612f5d198a66875e28847547d to catch related current and future operator infrastructure
  • Inspect macOS `defaults` domains on developer endpoints for anomalous randomized preference keys holding Base64-encoded blobs (fileless staging artifact)
  • Verify Telegram.app and other developer-installed applications against known-good code signatures; reinstall from the official source if ad-hoc signed or mismatched
  • Terminate and investigate any `chrome_remote`/CDP helper binaries and Chrome processes launched with remote-debugging flags outside expected developer tooling
  • Review and reset TCC automation permission grants (evidence of `tccutil reset AppleEvents` activity) and flag unexpected re-prompts disguised as System Settings or Xcode

Workarounds

  • Restrict Xcode project builds to code-reviewed, trusted repositories only; disable automatic Run Script execution on freshly cloned/untrusted projects
  • Disable Chrome's remote-debugging capability via managed policy on developer fleets where CDP is not operationally required
  • Require manual verification after any unexpected Chrome/Telegram process kill-and-relaunch prompt on developer workstations

Longer-term hardening

  • Deploy EDR/XDR with behavioral detection for fileless execution chains, anomalous AppleScript/osascript invocation, and unauthorized `defaults write` activity
  • Implement automated supply-chain dependency scanning on Xcode projects and CI pipelines to detect poisoned repositories before build
  • Enforce code-signing/notarization verification for macOS applications and alert when an ad-hoc-signed binary replaces a previously notarized one
  • Monitor and alert on termination of `CloudTelemetryService` and other Apple security telemetry processes
  • Establish network detection for CDP WebSocket connections to non-devtools, non-localhost endpoints
  • Correlate developer endpoint detections with repository, network, and identity telemetry in the SOC (per Unit 42's Cortex XSIAM guidance)

Weaknesses (CWE) in XCSSET v40: Fileless macOS Xcode-Supply-Chain Malware Adds

CWE-506, CWE-494, CWE-829, CWE-311

Timeline of XCSSET v40: Fileless macOS Xcode-Supply-Chain Malware Adds

  • Trend Micro's Mac Threat Response team discovers XCSSET, documenting Xcode-project injection and two zero-day exploits abusing Data Vaults and the Safari development version.
  • XCSSET is reported adding Chrome password-store abuse and a Telegram-account-theft AppleScript targeting the 'keepcoder.Telegram' Group Containers folder.
  • Microsoft-identified XCSSET variant, the first observed since 2022, is reported in limited attacks with enhanced obfuscation and expanded data theft (digital wallets, Notes app).
  • Microsoft Security Blog publishes full analysis of the revived XCSSET variant's new obfuscation and persistence techniques (run-only compiled AppleScripts, .zshrc_aliases, fake Launchpad via dockutil).
  • Microsoft documents further XCSSET evolution, including a Firefox-targeting clipper module and additional persistence updates.
  • XCSSET v40 begins spreading through supply-chain attacks hiding in the Xcode projects of dozens of legitimate applications with thousands of active users, after months of dormancy.
  • A second v40 deployment wave introduces the Telegram Desktop trojanizer (tdesktop) module alongside the existing Chrome DevTools Protocol backdoor (chrome_remote).
  • Unit 42 (Palo Alto Networks) publishes 'The Xcode Assassin Returns,' a full technical breakdown of XCSSET v40 including the broken identifier-substitution cipher, all 17 modules, and C2 infrastructure IOCs.

Sources cited for XCSSET v40: Fileless macOS Xcode-Supply-Chain Malware Adds

Detection coverage for TL-2026-1792

As of 2026-07-31, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1792 across Splunk SPL, Microsoft KQL and Sigma, covering 86 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
86 indicators of compromise · Red and above. Compare plans

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats