XCSSET version 40 has resurfaced to target macOS users by infecting compromised Xcode projects and GitHub repositories, spreading when developers build the poisoned code. The updated malware adds new Chrome hijacking and Telegram trojanizing modules, along with stronger evasion tactics and aggressive attempts to disable macOS security protections. #XCSSET #Xcode #GitHub #Unit42
Keypoints
- XCSSET v40 is targeting macOS users through compromised Xcode projects and GitHub repositories.
- The malware spreads when developers build infected projects, then propagates through shared source code.
- Unit 42 found 17 modules for credential theft, keylogging, clipboard manipulation, browser hijacking, and data exfiltration.
- The new version adds a Chrome hijacker and a Telegram trojanizer.
- XCSSET now uses stronger evasion methods and tries to disable macOS security tools like XProtect, MRT, TCC, and Rapid Security Response.