Threat reportMalwareTL-2026-1839
XCSSET v40 — macOS Developer Supply-Chain Malware Infecting Xcode Projects with Chrome CDP Hijacking and Telegram Trojanization
XCSSET v40 — macOS Developer Supply-Chain Malware Infecting (TL-2026-1839), also tracked as XCSSET v40, is a critical-severity malware campaign, first published 2026-08-03. It has no confirmed attribution, affects Apple macOS, maps to 21 MITRE ATT&CK techniques (T1005, T1020, T1027), and is covered by 9 detection rules and 29 indicators of compromise.
- Severity
- CRITICALAssessed severity
- CVEs
- 0None referenced
- Techniques
- 21MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 29Indicators of compromise
Key facts for TL-2026-1839
- Threat ID
- TL-2026-1839
- Also known as
- XCSSET v40, XCSSET, XCSSET 2026
- Severity
- CRITICAL
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- technology, software-development, finance
- Target regions
- South Asia, East Asia, Global
- Detection rules
- 9
- Indicators of compromise
- 29
Malware and tooling in XCSSET v40 — macOS Developer Supply-Chain Malware Infecting
Malware and tooling: XCSSET, telegram, 6e480d648fa1b70612f5d198a66875e28847547d
How XCSSET v40 — macOS Developer Supply-Chain Malware Infecting works
XCSSET v40 is a major re-architecture of the long-running macOS developer-targeting malware family, active since April 2026. It abuses compromised Xcode projects hosted on GitHub to infect developer workstations via a four-phase fileless execution pipeline. The malware hijacks Google Chrome through the Chrome DevTools Protocol (CDP) for credential theft and crypto-wallet interference, trojanizes Telegram Desktop by replacing the legitimate binary with a C2-controlled code-signed copy, and executes a multi-layered defense-evasion strategy targeting XProtect, MRT, TCC, and SoftwareUpdate. Payloads are delivered through dynamic rotating C2 infrastructure (60+ domains across .ru and .in TLDs), encrypted with AES-256-CBC using per-transmission randomized IVs and a dual-key architecture with separate inbound and outbound encryption keys.
XCSSET v40 represents the most significant evolution of the XCSSET malware family since its initial discovery by Trend Micro in August 2020. First documented by Palo Alto Networks' Unit 42 in their August 2026 report, this variant introduces a fundamentally re-architected execution model shifting from file-based persistence to a fully fileless, memory-resident operation.
The infection chain operates through a four-phase pipeline. In Phase 1 (Initial Compromise), a developer builds a poisoned Xcode project hosted on GitHub — the project's malicious run-script phase executes silently at build time, contacting the C2 via a curl to the /a endpoint with context p=xcode_phase. The payload generation dynamically scrambles its encoding, switching between hex and Base64 layers at compile time. In Phase 2 (Reconnaissance and Staging), the second-stage payload collects host metadata (uname -s, whoami) and transmits it to the C2. If the host profile passes anti-VM checks, the C2 returns a bash script obfuscated with a custom substitution cipher. In Phase 3 (Loader Wrappers), a main loader is downloaded to /tmp/r and an AppleScript wrapper is compiled on-the-fly as /tmp/p.app, executed in-memory via osascript, with both files deleted post-execution. In Phase 4 (Orchestrator), the boot module runs entirely in volatile memory, downloading 17 distinct module payloads from the C2 via /s/<encoded_module_name>, piping them to AppleScript for in-memory decryption and execution.
The two new operational components in v40 are the most concerning advancements. The chrome_remote module wraps the legitimate Google Chrome binary in a malicious persistence script. On each browser launch, CDP is activated on a predefined local port (port 18907), and the chrome_remote backdoor connects over a persistent WebSocket to the attacker C2. Through CDP, the module injects JavaScript before page load, hooks window.fetch and XMLHttpRequest for credential and API-token exfiltration, alters MetaMask cryptocurrency wallet addresses to manipulate dApp transactions, overrides password-manager autofill fields, and can escalate to a full fileless reverse shell by routing shell commands through browser console.log events received via the CDP WebSocket channel. Google has been notified and is extending existing Windows CDP protections to macOS. The tdesktop Telegram trojanizer module (first observed in May 2026 deployments) downloads a pre-built malicious Telegram.app ZIP from the C2, wipes the legitimate installation, drops a C2-controlled replacement signed ad hoc, kills the original Telegram process so the victim transparently relaunches the trojanized client, and manages state via AES-encrypted configuration blobs stored at ~/.tr and ~/.tr_map.
The malware deploys an unusually sophisticated defense-evasion strategy targeting multiple layers of macOS security. It disables SoftwareUpdate channels to block XProtect signature updates, MRT (Malware Removal Tool) updates, TCC database updates, and Rapid Security Response mechanisms. It spawns a Perl process that acquires and holds an exclusive file lock on XProtect's YARA rule database (XPdb), preventing signature updates from writing to disk. It runs a constant loop killing CloudTelemetryService to prevent Apple from receiving local security telemetry. When AppleEvents automation prompts are denied, it executes tccutil reset AppleEvents to clear the TCC decision database and re-presents prompts masquerading as System Settings or Xcode. The stats module performs anti-VM checks on CPU and hardware metadata, with VMs receiving no further payloads.
Polymorphism and encryption are implemented as a three-tier stack. At Layer 1 (Binary and Network Polymorphism), the loader binary is recompiled on the C2 every few hours — eight distinct hashes were observed for a single endpoint within a 24-hour window — and AES-256-CBC uses per-build keys with randomized IVs prepended to ciphertext. At Layer 2 (Network Dual-Key), inbound and outbound encryption use separate keys; the inbound key is embedded in the compiled AppleScript loader while the outbound key must be recovered from network telemetry, preventing defenders who retrieve one key from decrypting core malware logic. At Layer 3 (Source-Code Obfuscation), every string literal is encoded via a keyed Caesar cipher with randomized 52-character alphabets and variable shift values, and function/variable names are scrambled using server-side substitution ciphers applied before distribution. Unit 42 used AI-assisted pattern matching to break these ciphers and recover original identifiers.
C2 infrastructure spans over 60 registered domains across .ru and .in TLDs, aged for months before the attack wave to avoid detection flags on new registrations. The infrastructure uses a structured URI scheme with separate endpoints for loader downloads (/d/<binary_name>), module retrievals (/s/<encoded_module_name>), status logging (/l), file exfiltration (/u), heartbeat beacons (/p), and dynamic server-side configuration (/w?cbp for clipboard, /w?tr for Telegram). The operators weakened their own OPSEC by reusing SSL certificates (thumbprint 6e480d648fa1b70612f5d198a66875e28847547d), SSH keys, and RDP thumbprints across multiple campaigns, enabling infrastructure correlation. The 7 known C2 IPs span two hosting clusters: 91.108.106.229 and 95.142.35.x/95.142.37.x and 151.243.109.188 and 178.208.92.x.
Attribution remains unconfirmed. No named threat-actor group or nation-state has been formally tied to XCSSET across its six-year history (Trend Micro 2020, Microsoft 2025, Unit 42 2026). Historical indicators include a 2020 Twitter claim of authorship targeting Chinese developers and gambling businesses, along with documented ransom demands of 200 USDT from Chinese victims, suggesting primarily financially motivated cybercriminal activity rather than state-sponsored espionage. The geographic targeting has shifted in v40 toward South Asian developers (consistent with the introduction of .in TLD domains), while maintaining broader opportunistic targeting of the global macOS developer ecosystem.
MITRE ATT&CK techniques used in TL-2026-1839
Collection
T1005 Data from Local System; T1056 Input Capture
Exfiltration
Defense Evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1497 Virtualization/Sandbox Evasion
Execution
T1059 Command and Scripting Interpreter; T1204 User Execution
Command and Control
T1071 Application Layer Protocol; T1090 Proxy; T1573 Encrypted Channel
Initial Access
Impact
T1496 Resource Hijacking; T1565 Data Manipulation
Credential Access
T1539 Steal Web Session Cookie; T1555 Credentials from Password Stores
Persistence
T1543 Create or Modify System Process; T1546 Event Triggered Execution; T1547 Boot or Logon Autostart Execution
privilege-escalation
T1548 Abuse Elevation Control Mechanism
defense-impairment
Affected products and versions in XCSSET v40 — macOS Developer Supply-Chain Malware Infecting
- Apple — macOS
Vulnerable versions: All versions supporting Xcode and Chrome - Apple — Xcode
Vulnerable versions: All versions with build-phase run-script support - Google — Chrome for macOS
Vulnerable versions: All versions - CDP exposed via command-line arguments - Telegram — Telegram Desktop for macOS
Vulnerable versions: All versions - binary replaced by C2-supplied copy
Remediation for XCSSET v40 — macOS Developer Supply-Chain Malware Infecting
Immediate actions
- Isolate any macOS systems that have recently built Xcode projects from untrusted GitHub repositories
- Review Xcode build phases for unauthorized run-script entries in all projects
- Block all known C2 domains and IPs at DNS and perimeter firewall
- Inspect Chrome browser processes for CDP debugging port (18907) activity on macOS endpoints
- Check for unauthorized LaunchDaemon plists with com.google.* naming in /Library/LaunchDaemons
- Verify Telegram Desktop binary integrity via code signature check (codesign -dv /Applications/Telegram.app)
Workarounds
- Scan Xcode projects for unfamiliar build phases before building
- Monitor for unexpected Chrome instances running with --remote-debugging-port flags
- Audit macOS preferences domains for anomalous defaults entries
- Monitor for ad-hoc signed binaries executing from non-standard paths
- Enforce application allowlisting for developer workstations
Longer-term hardening
- Deploy behavioral EDR with AppleScript execution monitoring on macOS endpoints
- Implement file integrity monitoring for Xcode project build phases and run-scripts
- Deploy Cortex XDR or XSIAM with behavioral analytics for macOS threat detection
- Implement Advanced DNS Security and Advanced URL Filtering to disrupt C2 communication
- Establish developer workstation baseline with controlled build environments
- Deploy dependency scanning on all Xcode project dependencies before import
Timeline of XCSSET v40 — macOS Developer Supply-Chain Malware Infecting
- Trend Micro identifies first infected Xcode project on GitHub containing XCSSET malware
- Trend Micro publishes initial XCSSET discovery report documenting two zero-day exploits: Data Vaults cookie theft and Safari development version UXSS abuse
- Microsoft publishes analysis of new XCSSET variant with enhanced obfuscation, randomized payload generation, and three persistence mechanisms (zshrc, Dock fake Launchpad, Git pre-commit hooks)
- Microsoft publishes follow-up analysis of further XCSSET evolution adding LaunchDaemon persistence with com.google.* masquerading plists, Firefox targeting, and modified HackBrowserData binary
- First wave of XCSSET v40 infections detected by Unit 42 — introduces fileless execution, rotating C2 infrastructure with .ru/.in domains, and 17-module architecture
- Second wave of XCSSET v40 infections detected — adds Telegram Desktop trojanization module (tdesktop) and Chrome CDP hijacking backdoor (chrome_remote)
- Palo Alto Networks Unit 42 publishes comprehensive XCSSET v40 analysis detailing 17 modules, dual-key AES-256-CBC architecture, macOS preference-based fileless persistence, and detection guidance
Sources cited for XCSSET v40 — macOS Developer Supply-Chain Malware Infecting
- XCSSET v40: A Deep Dive Into the Latest XCSSET Version
- XCSSET v40 Infects Xcode Projects to Hijack Chrome and Trojanize Telegram
- New XCSSET Malware Adds New Obfuscation and Persistence Techniques
- XCSSET Evolves Again: Analyzing the Latest Updates to XCSSET's Inventory
- XCSSET Mac Malware Infects Xcode Projects, Uses 0-Days
- XCSSET v40 Abuses Chrome DevTools Protocol to Steal Cookies and Run Commands
- XCSSET v40 Infects Xcode Projects to Hijack Chrome and Trojanize Telegram on Macs
- MITRE ATT&CK: XCSSET (Software S0658)
Detection coverage for TL-2026-1839
As of 2026-08-03, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1839 across Splunk SPL, Microsoft KQL and Sigma, covering 29 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.