XCSSET v40 macOS malware activity via compromised Xcode projects
Malware Activity
Summary
Hide ▲
Show ▼
XCSSET v40 has resurfaced on macOS through compromised Xcode projects and GitHub repositories, putting thousands of users at risk of credential theft and data exfiltration. The malware is injected into benign project files and can execute when developers build the project, turning infected projects into a propagation path. The latest version adds a Chrome hijacker and Telegram trojanizer while expanding its evasion techniques. Its module set includes credential theft, keystroke logging, browser hijacking, and data exfiltration.
Related Happenings
Sysmon detection for Chrome and Edge process injection during CDP-enabled post-exploitation
Defensive Guidance
H score11
First: 14.08.2026 14:07
Last: 14.08.2026 14:07
Sources 1
About this happening:
A concrete Sysmon hunt for chrome.exe and msedge.exe injection now helps Windows defenders spot CDP-enabled post-exploitation before authenticated browser sessions...
Sysmon detection for Chrome and Edge process injection during CDP-enabled post-exploitation
Defensive GuidanceAbout this happening: A concrete Sysmon hunt for chrome.exe and msedge.exe injection now helps Windows defenders spot CDP-enabled post-exploitation before authenticated browser sessions...
AmnesiaStealer macOS infostealer distributed via ClickFix
Malware Activity
H score16
First: 14.08.2026 13:45
Last: 14.08.2026 13:45
Sources 1
About this happening:
AmnesiaStealer is a Rust-based macOS infostealer spread through a counterfeit GitHub "Download for macOS" page and ClickFix-style lure. It steals Keychain, b...
AmnesiaStealer macOS infostealer distributed via ClickFix
Malware ActivityAbout this happening: AmnesiaStealer is a Rust-based macOS infostealer spread through a counterfeit GitHub "Download for macOS" page and ClickFix-style lure. It steals Keychain, b...
AI Sidebar with Deepseek, ChatGPT, Claude, and more update/uninstall monetization payload
Malware Activity
H score11
First: 12.08.2026 17:09
Last: 12.08.2026 17:09
Sources 1
About this happening:
The AI Sidebar with Deepseek, ChatGPT, Claude, and more extension reintroduced a monetization payload that opens an affiliate link in a foreground tab on every updat...
AI Sidebar with Deepseek, ChatGPT, Claude, and more update/uninstall monetization payload
Malware ActivityAbout this happening: The AI Sidebar with Deepseek, ChatGPT, Claude, and more extension reintroduced a monetization payload that opens an affiliate link in a foreground tab on every updat...
BoryptGrab infostealer variant delivered via fake GitHub repositories
Malware Activity
H score30
First: 14.07.2026 22:15
Last: 14.07.2026 22:15
Sources 1
About this happening:
A BoryptGrab infostealer variant is being delivered through fake GitHub repositories, expanding a credential-theft operation that can drain browser, wallet, and messaging...
BoryptGrab infostealer variant delivered via fake GitHub repositories
Malware ActivityAbout this happening: A BoryptGrab infostealer variant is being delivered through fake GitHub repositories, expanding a credential-theft operation that can drain browser, wallet, and messaging...
Rust-based clipboard hijacker spreading via fake crypto tools
Malware Activity
H score13
First: 18.06.2026 18:00
Last: 18.06.2026 18:00
Sources 1
About this happening:
A Rust-based clipboard hijacker is spreading through fake crypto tools and silently replacing copied wallet addresses, putting Windows and macOS users at risk of theft...
Rust-based clipboard hijacker spreading via fake crypto tools
Malware ActivityAbout this happening: A Rust-based clipboard hijacker is spreading through fake crypto tools and silently replacing copied wallet addresses, putting Windows and macOS users at risk of theft...
Timeline
-
04.08.2026 22:03 2 articles · 13d ago
XCSSET v40 targets macOS users through compromised Xcode projects
Initial DisclosureXCSSET version 40 resurfaced after months of inactivity and was observed in two attack waves in mid-April and early May, targeting thousands of macOS users through compromised Xcode projects and GitHub repositories. Researchers at Palo Alto Networks Unit 42 said the malware is injected into benign project files, executes when developers build the project, propagates through shared source code, and adds a Chrome hijacker, a Telegram trojanizer, and new detection-evasion measures.
Show sources
- New XCSSET variant targets macOS devs via compromised Xcode projects — www.bleepingcomputer.com — 04.08.2026 22:03
- New XCSSET variant targets macOS devs via compromised Xcode projects — www.bleepingcomputer.com — 04.08.2026 22:03