New XCSSET macOS malware campaign spreads through compromised Xcode projects and GitHub repositories

A new version of the XCSSET malware is infecting macOS developers through poisoned Xcode projects shared in compromised GitHub repositories. Palo Alto Networks' Unit 42 says XCSSET v40 appeared in attack waves in mid-April and early May 2026, using injected downloader scripts in legitimate project files; once built, it can spread to other local Xcode projects and deploy modules for credential theft, keylogging, browser hijacking, clipboard manipulation, data theft, and a new Telegram trojanizer.
Why it matters: Developers who build untrusted Xcode projects are at risk of having their Macs, browser sessions, and even cryptocurrency transactions hijacked. Organizations with macOS development teams should urgently scan repositories and build pipelines for tampering, monitor for the indicators described, and treat shared Xcode projects as a supply-chain risk.

Sources

New XCSSET variant targets macOS devs via compromised Xcode projects
Bill Toulas 2026.08.04 100% relevant
This article establishes a distinct 2026 XCSSET malware resurgence centered on compromised Xcode projects and GitHub repositories, with newly reported v40 features, attack waves, and macOS-focused evasion and theft capabilities.
← Back to all stories