XCSSET v40 macOS malware activity via compromised Xcode projects
Malware Activity
Updated: 04.08.2026 22:03
· First: 04.08.2026 22:03
· 📰 1 src / 1 articles
· H score: 30
XCSSET v40 has resurfaced on macOS through compromised Xcode projects and GitHub repositories, putting thousands of users at risk of credential theft and data exfiltration. The malware is injected into benign project files and can execute when developers build the project, turning infected projects into a propagation path. The latest version adds a Chrome hijacker and Telegram trojanizer while expanding its evasion techniques. Its module set includes credential theft, keystroke logging, browser hijacking, and data exfiltration.