XCSSET Malware Variant Targets macOS Developers via Supply Chain
cyb3rops · x · 2026-08-04
Unit 42 disclosed that after months of dormancy, the XCSSET malware released version 40 (v40) targeting the macOS ecosystem.
- Propagation: Since April 2026, the malware has spread via supply chain attacks by hiding in Xcode projects of dozens of legitimate apps with thousands of active users. It enhanced worming capabilities on GitHub, infecting all existing Xcode projects on a compromised system.
- Stealth & Damage: V40 combines polymorphic payload generation, fileless persistence, and dynamic in-memory execution. It hides core logic in memory space and weakens security mechanisms, using multi-layered ciphers for obfuscation.
- Response: Researchers leveraged advanced AI and pattern-matching algorithms to de-obfuscate the logic and revealed the attackers' rotating C2 infrastructure.
More from coding & agent
- Can AI Coding Agents Crack Nvidia's CUDA Moat? — bingxu_ · 2026-08-04
- HeyGen LiveAvatar Agent Builds $3M Pipeline During 8-Week Employee Leave — HeyGen · 2026-08-04
- Agent Benchmark Reflections: Scores Are Deceptive, Open-source Trajectories Needed — Shahules786 · 2026-08-04
- Agent Benchmark Flaws: Over-specified Verifiers Penalize Semantically Correct Actions — Shahules786 · 2026-08-04
- ITSMBench: Open-Sourcing a Benchmark for Enterprise AI Agents — Shahules786 · 2026-08-04
- Protecting AI Attention: The Essence of Inference Efficiency — DanWahlin · 2026-08-04