XCSSET macOS malware new variant with clipboard hijacking and persistence
Malware Activity
Summary
Hide ▲
Show ▼
A new XCSSET macOS malware variant has been observed in limited attacks against Xcode projects used by developers. It expands browser data theft, including Firefox, and uses clipboard hijacking to replace cryptocurrency wallet or payment addresses. The variant also strengthens persistence on macOS with LaunchDaemon-based mechanisms and additional stealth features such as run-only compiled AppleScripts, encryption, obfuscation, and a fake System Settings.app lure. The activity increases the risk of credential theft, browser-data theft, and cryptocurrency diversion on infected systems.
Related Happenings
SHub Reaper macOS infostealer variant
Malware Activity
First: 19.05.2026 00:42
Last: 19.05.2026 00:42
Sources 1
About this happening:
The **SHub Reaper** macOS infostealer now uses **AppleScript** and a fake **Apple security update** lure to infect Macs, raising the risk of credential theft and remote access. It...
SHub Reaper macOS infostealer variant
Malware ActivityAbout this happening: The **SHub Reaper** macOS infostealer now uses **AppleScript** and a fake **Apple security update** lure to infect Macs, raising the risk of credential theft and remote access. It...
GlassWorm OpenVSX sleeper extension campaign
Campaign
First: 28.04.2026 00:41
Last: 28.04.2026 00:41
Sources 1
About this happening:
The **GlassWorm** operation has launched a **new wave** against **OpenVSX**, seeding **73 sleeper extensions** that become malicious after an **update** and can deliver malware to...
GlassWorm OpenVSX sleeper extension campaign
CampaignAbout this happening: The **GlassWorm** operation has launched a **new wave** against **OpenVSX**, seeding **73 sleeper extensions** that become malicious after an **update** and can deliver malware to...
MiningDropper (BeatBanker) modular Android payload framework with encrypted staging
Technical Analysis
First: 24.04.2026 14:48
Last: 24.04.2026 14:48
Sources 1
About this happening:
**MiningDropper (BeatBanker)** now stands out as a **layered modular Android malware framework** that can reuse one delivery chain across **hundreds of samples**, making **static...
MiningDropper (BeatBanker) modular Android payload framework with encrypted staging
Technical AnalysisAbout this happening: **MiningDropper (BeatBanker)** now stands out as a **layered modular Android malware framework** that can reuse one delivery chain across **hundreds of samples**, making **static...
GlassWorm Zig dropper infecting developer IDEs
Malware Activity
First: 10.04.2026 16:23
Last: 10.04.2026 16:23
Sources 1
About this happening:
The **GlassWorm** malware set now uses a **Zig dropper** that can silently infect **all VS Code-based IDEs** on a developer's machine, widening the reach of the compromise. The pa...
GlassWorm Zig dropper infecting developer IDEs
Malware ActivityAbout this happening: The **GlassWorm** malware set now uses a **Zig dropper** that can silently infect **all VS Code-based IDEs** on a developer's machine, widening the reach of the compromise. The pa...
Atomic Stealer (AMOS) macOS ClickFix Script Editor activity
Malware Activity
First: 09.04.2026 14:20
Last: 09.04.2026 14:20
Sources 1
About this happening:
A **macOS** malware campaign has shifted its **ClickFix** execution flow to **Script Editor**, helping **Atomic Stealer (AMOS)** avoid the usual **Terminal** warning path. The cha...
Atomic Stealer (AMOS) macOS ClickFix Script Editor activity
Malware ActivityAbout this happening: A **macOS** malware campaign has shifted its **ClickFix** execution flow to **Script Editor**, helping **Atomic Stealer (AMOS)** avoid the usual **Terminal** warning path. The cha...
Timeline
-
26.09.2025 12:09 2 articles · 8mo ago
Updated XCSSET macOS malware variant is disclosed
Initial DisclosureMicrosoft Threat Intelligence disclosed an updated XCSSET macOS malware variant that was observed in limited attacks against Xcode projects used by software developers. The variant adds Firefox browser data theft, clipboard hijacking that replaces cryptocurrency wallet addresses, and a new LaunchDaemon persistence mechanism, while also using run-only compiled AppleScripts, encryption, and obfuscation to help stealthy execution.
Show sources
- New macOS XCSSET Variant Targets Firefox with Clipper and Persistence Module — thehackernews.com — 26.09.2025 12:09
- New macOS XCSSET Variant Targets Firefox with Clipper and Persistence Module — thehackernews.com — 26.09.2025 12:09
-
26.09.2025 01:49 2 articles · 8mo ago
Microsoft details new XCSSET macOS variant
Technical Analysis UpdateMicrosoft Threat Intelligence reports a new XCSSET macOS malware variant seen in limited attacks against Xcode projects used by macOS developers. The variant adds Firefox data theft through a modified HackBrowserData build, clipboard hijacking that swaps cryptocurrency addresses, and stronger persistence using LaunchDaemon entries and a fake System Settings.app in /tmp. Microsoft also shared findings with Apple and is working with GitHub to remove associated repositories.
Show sources
- Microsoft warns of new XCSSET macOS malware variant targeting Xcode devs — www.bleepingcomputer.com — 26.09.2025 01:49
- Microsoft warns of new XCSSET macOS malware variant targeting Xcode devs — www.bleepingcomputer.com — 26.09.2025 01:49