Find notable cyber news and cases, enriched with sources, timelines, and signals.

XCSSET v40 macOS malware activity via compromised Xcode projects

Malware Activity
First reported
Last updated
Happening score
H score 30
1 unique sources, 1 articles

Summary

Hide ▲

XCSSET v40 has resurfaced on macOS through compromised Xcode projects and GitHub repositories, putting thousands of users at risk of credential theft and data exfiltration. The malware is injected into benign project files and can execute when developers build the project, turning infected projects into a propagation path. The latest version adds a Chrome hijacker and Telegram trojanizer while expanding its evasion techniques. Its module set includes credential theft, keystroke logging, browser hijacking, and data exfiltration.

Related Happenings

Sysmon detection for Chrome and Edge process injection during CDP-enabled post-exploitation

Defensive Guidance
H score11 First: 14.08.2026 14:07 Last: 14.08.2026 14:07 Sources 1

About this happening: A concrete Sysmon hunt for chrome.exe and msedge.exe injection now helps Windows defenders spot CDP-enabled post-exploitation before authenticated browser sessions...

AmnesiaStealer macOS infostealer distributed via ClickFix

Malware Activity
H score16 First: 14.08.2026 13:45 Last: 14.08.2026 13:45 Sources 1

About this happening: AmnesiaStealer is a Rust-based macOS infostealer spread through a counterfeit GitHub "Download for macOS" page and ClickFix-style lure. It steals Keychain, b...

AI Sidebar with Deepseek, ChatGPT, Claude, and more update/uninstall monetization payload

Malware Activity
H score11 First: 12.08.2026 17:09 Last: 12.08.2026 17:09 Sources 1

About this happening: The AI Sidebar with Deepseek, ChatGPT, Claude, and more extension reintroduced a monetization payload that opens an affiliate link in a foreground tab on every updat...

BoryptGrab infostealer variant delivered via fake GitHub repositories

Malware Activity
H score30 First: 14.07.2026 22:15 Last: 14.07.2026 22:15 Sources 1

About this happening: A BoryptGrab infostealer variant is being delivered through fake GitHub repositories, expanding a credential-theft operation that can drain browser, wallet, and messaging...

Rust-based clipboard hijacker spreading via fake crypto tools

Malware Activity
H score13 First: 18.06.2026 18:00 Last: 18.06.2026 18:00 Sources 1

About this happening: A Rust-based clipboard hijacker is spreading through fake crypto tools and silently replacing copied wallet addresses, putting Windows and macOS users at risk of theft...

Timeline

  1. 04.08.2026 22:03 2 articles · 13d ago

    XCSSET v40 targets macOS users through compromised Xcode projects

    Initial Disclosure

    XCSSET version 40 resurfaced after months of inactivity and was observed in two attack waves in mid-April and early May, targeting thousands of macOS users through compromised Xcode projects and GitHub repositories. Researchers at Palo Alto Networks Unit 42 said the malware is injected into benign project files, executes when developers build the project, propagates through shared source code, and adds a Chrome hijacker, a Telegram trojanizer, and new detection-evasion measures.

    Show sources