# XCSSET v40: Fileless macOS Xcode-Supply-Chain Malware Adds Chrome DevTools Protocol Hijacking and Telegram Trojanization

> Unit 42 documents XCSSET version 40, a macOS malware family propagating via infected Xcode projects on GitHub that now hides its core logic in memory using polymorphic payload generation, fileless persistence via the macOS `defaults` system, and a multi-layered cipher scheme. v40 adds a Chrome DevTools Protocol (CDP) hijacking backdoor and a Telegram Desktop trojanizer module, and actively impairs XProtect, TCC, and Apple's software-update defenses while primarily targeting developers across South Asia.

- **Published:** 2026-07-31T00:00:00Z
- **Last reviewed:** 2026-07-31T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1792
- **ID:** TL-2026-1792
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 86 (full data via the Threadlinqs MCP server — Purple tier)

## Description

XCSSET is a modular macOS malware family, first documented by Trend Micro in August 2020, that propagates by injecting malicious Run Script build phases and git pre-commit hooks into Xcode projects hosted on GitHub and other developer repositories. When an infected project is built, the injected script triggers a four-stage execution chain: (1) an initial loader with an encoded payload runs during the Xcode build phase; (2) a host-reconnaissance step collects OS type, username, and serial number via curl requests to the C2; (3) a staging step downloads loader binaries, wraps them in temporary AppleScript, executes them in memory via osascript, and deletes the disk artifacts; and (4) a core 'boot' orchestrator module retrieves and runs up to 17 additional functional modules entirely in memory from C2 infrastructure. Propagation continues through recursive traversal of user directories to infect zip-archived Xcode projects and through git pre-commit hook injection, alongside classic trojanized-application distribution.

Version 40 (deployed from early April 2026, with a second wave in May 2026 after months of dormancy) is a substantial architectural upgrade over the intermediate variants Microsoft documented in March and September 2025. It introduces a novel fileless persistence mechanism that abuses the macOS `defaults` preference system (functionally analogous to the Windows Registry) to store Base64-encoded staging payloads under randomized preference keys (e.g. `mpirv_eahpi_apm`); when a trojanized application later launches, a single command retrieves, decodes, and re-executes the payload, tagging the resulting session with a source-identification (SRC) parameter. Evasion is layered at both the binary and network levels: the loader binary is recompiled on the C2 server every few hours (eight distinct SHA hashes were observed within 24 hours), in-memory modules are encrypted with AES-256-CBC using per-build keys and randomized IVs so identical modules sent seconds apart yield different ciphertext, and a dual-key architecture separates the inbound decryption key embedded in the AppleScript loader from a distinct outbound key, denying defenders who only capture network telemetry the ability to decrypt core logic. Source code itself is protected pre-compilation by a substitution cipher applied to function, module, and variable names (with no decryption mapping left on the endpoint) and a per-module keyed Caesar cipher using randomized 52-character alphabets and variable shift values for string literals; Unit 42 states it broke the identifier-substitution scheme using pattern matching assisted by an LLM, recovering the operators' original module/function names.

The two headline new modules in v40 are `chrome_remote` and `tdesktop`. `chrome_remote` wraps the legitimate Google Chrome binary in a malicious persistence script that, on every Chrome launch, restarts the XCSSET `boot` module, relaunches Chrome with the Chrome DevTools Protocol (CDP) enabled on a pre-defined local port, and drops/executes a dedicated `chrome_remote` binary that connects to that CDP port. This establishes a persistent WebSocket channel to the C2 for real-time JavaScript payload delivery and pre-page-load code injection, and overrides critical browser APIs: it hooks `window.fetch`/`XMLHttpRequest` to exfiltrate credentials and API tokens, intercepts the injected MetaMask Ethereum provider to manipulate wallet addresses and interfere with dApp transactions, and overrides password-manager autofill fields to harvest stored credentials. It also implements a fileless reverse shell by monitoring console-logging events for operator command strings, executing them via a shell handler, and returning output over the same CDP WebSocket. `tdesktop`, new as of the May 2026 wave, escalates XCSSET's historical Telegram data theft into full application trojanization: it downloads a pre-built malicious Telegram.app ZIP from the C2, kills the running legitimate Telegram process, replaces it with the ad-hoc-signed trojanized copy, and forces the victim to relaunch the compromised binary. A custom AES-encrypted configuration is pulled from a dedicated `/w?tr` C2 endpoint, decrypted to `~/.tr` with a companion state file at `~/.tr_map`, and both are periodically uploaded back to the C2 as `base_tr_file.txt` / `base_tr_map.txt`.

v40 also actively impairs macOS's own defense stack: it disables the SoftwareUpdate configuration channel to block automatic retrieval of XProtect, MRT, and TCC signature databases and to prevent access to Apple's Rapid Security Response channel; it runs a constant loop that terminates the `CloudTelemetryService` process to stop local security telemetry from reaching Apple (and thereby keep operator tooling out of future XProtect signature updates); it spawns a Perl process that acquires an exclusive file lock on the XProtect YARA-rule database (XPdb) to block signature writes to disk; and it invokes `tccutil reset AppleEvents` to wipe existing TCC decisions, then re-presents automation permission prompts disguised as System Settings or Xcode so the victim unknowingly re-grants the access XCSSET needs. A dedicated `stats` reconnaissance module performs CPU/hardware anti-VM checks before any further modules are delivered, evading automated sandbox analysis.

Targeting remains centered on software developers in the Apple ecosystem, with elevated concentration in South Asia consistent with Trend Micro's original 2020 reporting; Unit 42 states the campaign has spread through dozens of legitimate applications with thousands of active users since early April 2026. C2 infrastructure comprises roughly 40 domains registered in early 2026 across four staggered bursts and aged for months before the April attack wave to evade newly-registered-domain detection, showing a geographic pivot from 2025's `.ru`-themed CDN/tech-property lures to 2026 `.in` domains that mirror identically-named `.ru` siblings. The C2 protocol uses a small fixed set of HTTP(S) endpoints (`/d` binary download, `/a` stager retrieval, `/s` AppleScript module retrieval, `/l` status/log POST, `/u` file exfiltration POST, `/p` heartbeat, `/w?<cmd>` dynamic per-module configuration, `/e` browser-hijack event POST). Notable operator OPSEC failures let Unit 42 cluster all four identified operator IP addresses by a single shared SSL certificate thumbprint, plus reused SSH keys and a shared self-signed RDP certificate, cross-contaminating infrastructure across otherwise-separated XCSSET campaigns. No BeaconBeagle correlation matches were returned for the queried C2 IPs/domains as of 2026-07-31.

## MITRE ATT&CK

- T1583.001 Domains
- T1588.002 Tool
- T1195.001 Compromise Software Dependencies and Development Tools
- T1059.002 AppleScript
- T1204.002 Malicious File
- T1554 Compromise Host Software Binary
- T1543.004 Launch Daemon
- T1546.004 Unix Shell Configuration Modification
- T1543.004 Launch Daemon
- T1546.004 Unix Shell Configuration Modification
- T1112 Modify Registry
- T1027 Obfuscated Files or Information
- T1140 Deobfuscate/Decode Files or Information
- T1620 Reflective Code Loading
- T1685 Disable or Modify Tools
- T1553.002 Code Signing
- T1036.005 Match Legitimate Resource Name or Location
- T1497.001 System Checks
- T1555 Credentials from Password Stores
- T1539 Steal Web Session Cookie
- T1082 System Information Discovery
- T1497.001 System Checks
- T1217 Browser Information Discovery
- T1115 Clipboard Data
- T1056.001 Keylogging
- T1213 Data from Information Repositories
- T1005 Data from Local System
- T1185 Browser Session Hijacking
- T1071.001 Web Protocols
- T1573.001 Symmetric Cryptography
- T1132.001 Standard Encoding
- T1104 Multi-Stage Channels
- T1008 Fallback Channels
- T1105 Ingress Tool Transfer
- T1041 Exfiltration Over C2 Channel

## Sources

- [The Xcode Assassin Returns: A Deep Dive Into the Latest XCSSET Version](https://unit42.paloaltonetworks.com/xcsset-v40-malware-analysis/)
- [New XCSSET malware adds new obfuscation, persistence techniques to infect Xcode projects](https://www.microsoft.com/en-us/security/blog/2025/03/11/new-xcsset-malware-adds-new-obfuscation-persistence-techniques-to-infect-xcode-projects/)
- [XCSSET evolves again: Analyzing the latest updates to XCSSET's inventory](https://www.microsoft.com/en-us/security/blog/2025/09/25/xcsset-evolves-again-analyzing-the-latest-updates-to-xcssets-inventory/)
- [XCSSET Mac Malware Infects Xcode Projects, Uses 0-Days](https://www.trendmicro.com/en_us/research/20/h/xcsset-mac-malware--infects-xcode-projects--uses-0-days.html)
- [The XCSSET info-stealing malware is back, targeting macOS users and devs](https://www.helpnetsecurity.com/2025/02/17/the-xcsset-info-stealing-malware-is-back-targeting-macos-users-and-devs/)
- [Microsoft Uncovers New XCSSET macOS Malware Variant with Advanced Obfuscation Tactics](https://thehackernews.com/2025/02/microsoft-uncovers-new-xcsset-macos.html)
- [Nasty macOS Malware XCSSET Now Targets Google Chrome, Telegram Software](https://thehackernews.com/2021/07/nasty-macos-malware-xcsset-now-targets.html)
- [XCSSET Malware Is Stealing Telegram Accounts and Google Chrome Data](https://heimdalsecurity.com/blog/a-macos-malware-is-stealing-telegram-accounts-and-google-chrome-data/)
- [XCSSET, a MacOS malware, Targets Google Chrome and Telegram Software](https://www.ehackingnews.com/2021/07/xcsset-macos-malware-targets-google.html)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1792
