# XCSSET v40 macOS Malware Targeting Developers via Compromised Xcode Projects

> XCSSET v40, a new variant of the modular macOS malware family first discovered in 2020, has resurfaced with two attack waves (April and May 2026) targeting developers across South Asia through compromised Xcode projects on GitHub. The malware deploys 17 modules including two new components — a Chrome DevTools Protocol (CDP) backdoor enabling full browser session control and a fileless reverse shell, and a Telegram Desktop trojanizer — with polymorphic payload generation, dual-key AES-256-CBC encryption, and aggressive macOS security feature suppression (XProtect, MRT, TCC, Rapid Security Response).

- **Published:** 2026-08-04T00:00:00Z
- **Last reviewed:** 2026-08-04T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1870
- **ID:** TL-2026-1870
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 28 (full data via the Threadlinqs MCP server — Purple tier)

## Description

XCSSET is a long-running macOS malware family first documented by Trend Micro in August 2020, notable for infecting Xcode projects to create supply-chain risks for macOS developers. The malware injects malicious build-phase scripts into .xcodeproj files so that compiling the project triggers execution. Version 40 (v40), analyzed by Palo Alto Networks Unit 42 after a dormant period, represents a significant escalation in capability and stealth.

The infection chain operates in four stages. Stage 1: an attacker compromises Git repositories and injects a downloader script into the Xcode project build phases of legitimate .xcodeproj files; when a developer builds the project locally, a run-script phase executes silently, contacting the C2 via curl to /a with parameter p=xcode_phase. Stage 2: the staging payload performs reconnaissance — querying uname -s (OS type) and whoami (username) — exfiltrating host metadata to the C2. Stage 3: the C2 returns a Bash script obfuscated via a custom substitution cipher, performing hardware fingerprinting against targeted serial profiles, then pulling the primary loader to /tmp/r and compiling an AppleScript wrapper as /tmp/p.app; the loader executes in-memory via osascript. Stage 4: the main orchestrator (named 'boot') runs entirely in memory, retrieving additional modules from the C2 via HTTPS, piping payloads to AppleScript for in-memory decryption and execution, then terminating all staging processes and deleting installation files from disk.

XCSSET v40 delivers 17 modular components, each with a distinct function. The orchestrator 'boot' dispatches modules including stats (reconnaissance, anti-VM, browser extension exfiltration), clipboard_v2 (keyboard hijacker), payloader (secondary dispatcher), replicator_finder (Xcode project file infector), git_finder (Git pre-commit hook infector), zip_infect_finder (NEW — traverses directories to find/infect Xcode projects inside .zip archives), data_folders_finder (C2-driven folder finder and exfiltrator), firefox_data (Firefox infostealer), notes_app (Apple Notes exfiltrator), settings_app (LaunchDaemon persistence via fake Settings.app; blocks XProtect), finder_app (TCC permission abuse; creates trojanized apps mimicking Finder/Xcode/Terminal/Reminders/SimulatorTrampoline), persist (.zshrc and Dock-based persistence), browser_remote (unified browser hijack dispatcher), safari_remote (Safari hijacker), chrome_remote (NEW — Chrome CDP backdoor), and tdesktop (NEW — Telegram Desktop trojanizer).

The two new modules in v40 are the most significant additions. The Chrome hijacker (chrome_remote) wraps the legitimate Google Chrome binary in a malicious launcher: when Chrome launches, the malware restarts the boot orchestrator, activates Chrome DevTools Protocol (CDP) on localhost:18907, and drops a helper binary that connects to CDP. This helper establishes a persistent WebSocket connection to the C2, injects JavaScript before pages load, hooks window.fetch and XMLHttpRequest to exfiltrate credentials and API tokens, intercepts MetaMask's Ethereum provider to manipulate cryptocurrency transactions, and overrides password-manager autofill fields. It also monitors browser console events; when the operator sends a console.log with a specific delimiter prefix, chrome_remote executes the payload via exec.Command on the host, creating a fileless reverse shell routed through the CDP WebSocket. Google has protections against CDP abuse on Windows and is extending defenses to macOS.

The Telegram Desktop trojanizer (tdesktop), which appeared in the May 2026 wave but not the April deployment, downloads a pre-built malicious Telegram.app ZIP from the C2, deletes the legitimate copy, drops the replacement, ad hoc code-signs it, and kills the original Telegram process so the victim relaunches the trojanized copy. Its configuration is AES-encrypted and stored in ~/.tr.

XCSSET v40 employs aggressive evasion. The loader binary is recompiled on the C2 every few hours — Unit 42 observed 8 distinct hashes delivered to one endpoint in 24 hours. A dual-key encryption architecture uses separate AES-256-CBC keys for inbound versus outbound C2 traffic; the inbound key embedded in the compiled AppleScript loader means network telemetry alone cannot decrypt core logic. String literals use per-module keyed Caesar ciphers with randomized 52-character alphabets and variable shift values, ensuring no two builds share common string signatures. Function, module, and variable names are scrambled server-side via a substitution cipher before distribution, with the decryption mapping absent from the endpoint.

The malware aggressively disables macOS security: it blocks XProtect signature updates, disables MRT (Malware Removal Tool) updates, resets the TCC database, blocks Rapid Security Response delivery, and runs a constant loop terminating Apple's CloudTelemetryService. It spawns a Perl process to acquire and hold an exclusive file lock on the YARA-rule database (XPdb), preventing security update writes. When the user denies AppleEvents automation, it invokes tccutil reset AppleEvents and re-prompts with a dialog masquerading as System Settings or Xcode. The stats module performs anti-VM checks via CPU and hardware metadata and withholds module delivery from identified virtual machines.

C2 infrastructure includes approximately 64 domains registered in four short bursts during early 2026 from a small IP pool, aged for months before activation to bypass new-domain detection. Domains shifted from .ru TLDs in 2025 campaigns to .in TLDs in 2026, consistent with South Asian targeting. Operator OPSEC failures include cross-contaminated IP addresses across different XCSSET campaigns, a shared SSL certificate thumbprint (6e480d648fa1b70612f5d198a66875e28847547d) across all four operator IPs, and reused SSH keys and a self-signed RDP certificate.

Attribution remains unclear; no named APT group or nation-state has been assigned. Geographic targeting concentrates on South Asia, consistent with Trend Micro's 2020 reporting. The primary motivation appears financial given the cryptocurrency address manipulation, credential theft, and session hijacking, though the malware's data exfiltration capabilities could serve espionage objectives. The supply-chain vector targeting macOS developers through GitHub compromises gives the malware exceptional reach, with infected Xcode projects belonging to dozens of legitimate applications with thousands of active users.

## MITRE ATT&CK

- T1195 Supply Chain Compromise
- T1059 Command and Scripting Interpreter
- T1204 User Execution
- T1543 Create or Modify System Process
- T1547 Boot or Logon Autostart Execution
- T1554 Compromise Host Software Binary
- T1574 Hijack Execution Flow
- T1055 Process Injection
- T1027 Obfuscated Files or Information
- T1140 Deobfuscate/Decode Files or Information
- T1497 Virtualization/Sandbox Evasion
- T1685 Disable or Modify Tools
- T1036 Masquerading
- T1056 Input Capture
- T1555 Credentials from Password Stores
- T1185 Browser Session Hijacking
- T1518 Software Discovery
- T1082 System Information Discovery
- T1560 Archive Collected Data
- T1071 Application Layer Protocol
- T1573 Encrypted Channel
- T1489 Service Stop

## Sources

- [The Xcode Assassin Returns: A Deep Dive Into the Latest XCSSET Version (Unit 42)](https://unit42.paloaltonetworks.com/xcsset-v40-malware-analysis/)
- [New XCSSET variant targets macOS devs via compromised Xcode projects (BleepingComputer)](https://www.bleepingcomputer.com/news/security/new-xcsset-variant-targets-macos-devs-via-compromised-xcode-projects/)
- [XCSSET Mac Malware Infects Xcode Projects, Uses 0-Days (Trend Micro)](https://www.trendmicro.com/en_us/research/20/h/xcsset-mac-malware--infects-xcode-projects--uses-0-days.html)
- [XCSSET Update: Browser Debug Modes, Inactive Ransomware (Trend Micro)](https://www.trendmicro.com/en_us/research/20/i/xcsset-update-browser-debug-modes-inactive-ransomware.html)
- [New XCSSET malware adds new obfuscation, persistence techniques to infect Xcode projects (Microsoft)](https://www.microsoft.com/en-us/security/blog/2025/03/11/new-xcsset-malware-adds-new-obfuscation-persistence-techniques-to-infect-xcode-projects/)
- [XCSSET evolves again: Analyzing the latest updates to XCSSET's inventory (Microsoft)](https://www.microsoft.com/en-us/security/blog/2025/09/25/xcsset-evolves-again-analyzing-the-latest-updates-to-xcssets-inventory/)
- [XCSSET v40 Abuses Chrome DevTools Protocol to Steal Cookies and Run Commands (HEAL Security)](https://healsecurity.com/xcsset-v40-abuses-chrome-devtools-protocol-to-steal-cookies-and-run-commands/)
- [XCSSET Malware Returns in macOS Attacks That Hijack Chrome (CyberInsider)](https://cyberinsider.com/xcsset-malware-returns-in-macos-attacks-that-hijack-chrome/)
- [XCSSET v40 Technical Breakdown of Chrome CDP Abuse (CyberNexora)](https://blog.cybernexora.com/xcsset-v40/)
- [XCSSET Mac Malware Steals Information, Spreads via Xcode Projects (SecurityWeek)](https://www.securityweek.com/xcsset-mac-malware-steals-information-spreads-xcode-projects/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1870
