discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.
Featured

New XCSSET variant targets macOS devs via compromised Xcode projects

A new version of the XCSSET malware targets thousands of macOS users through compromised Xcode projects and GitHub repositories. The malware features enhanced evasion techniques and introduces two new components.

By Bill Toulas·Aug 4·bleepingcomputer.com·2 min read

Intelligence analysis by Llama

New XCSSET variant targets macOS devs via compromised Xcode projects
Image: bleepingcomputer.com

A new XCSSET variant targets macOS developers via compromised Xcode projects and GitHub repositories. The malware features enhanced evasion techniques and introduces two new components.

Why it matters

This story matters to someone following Security because it highlights a new variant of the XCSSET malware that targets macOS developers. The malware's enhanced evasion techniques and new components make it a significant threat.

Imagine you're a developer working on a project, and you download a compromised Xcode project from the internet. This project contains a hidden malware that can steal your login credentials, track your browsing history, and even hijack your Chrome browser. The malware can also spread to other projects on your system and even to other people's systems if they download the same project.

Analysis

A New Variant of XCSSET Emerges

A new version of the XCSSET malware has been discovered, targeting thousands of macOS users through compromised Xcode projects and GitHub repositories. This variant, version 40, features enhanced evasion techniques and introduces two new components, a Chrome hijacker and a Telegram trojanizer.

The Chrome hijacker wraps the Chrome browser in a malicious launcher and enables the Chrome DevTools Protocol (CDP) on a local port to fetch JavaScript from the attacker's command-and-control (C2) infrastructure. This allows the attackers to intercept web traffic, including credentials, cookies, and MetaMask transactions, which can be manipulated on the fly to divert payments.

The Telegram trojanizer deletes the legitimate Telegram Desktop application on infected systems and replaces it with a malicious version, potentially used for intercepting victims' communications. However, the exact functionality of this component remains unknown due to the encrypted configuration.

Detection-Evasion Measures

The new XCSSET variant features several detection-evasion measures, including periodically re-compiling the loader on the C2 server, using separate encryption keys for inbound and outbound communications, and obfuscating function names, variables, and strings with build-unique ciphers.

The malware also aggressively attempts to disable macOS security features such as XProtect, MRT, TCC, and Rapid Security Response, terminates Apple's CloudTelemetryService, and prevents XProtect signature updates.

Defending Against XCSSET

To defend against the latest version of XCSSET, researchers recommend monitoring for anomalous AppleScript activity, unauthorized browser modifications, suspicious macOS defaults domains, and ad hoc-signed applications that bypass Gatekeeper.

Additionally, scanning open-source dependencies to prevent compromised repositories from entering software development pipelines is crucial in preventing the spread of the malware.

Key points

  • A new variant of the XCSSET malware has been discovered, targeting thousands of macOS users through compromised Xcode projects and GitHub repositories.
  • The malware features enhanced evasion techniques and introduces two new components, a Chrome hijacker and a Telegram trojanizer.
  • The Chrome hijacker allows attackers to intercept web traffic, including credentials, cookies, and MetaMask transactions.
  • The Telegram trojanizer deletes the legitimate Telegram Desktop application and replaces it with a malicious version.
  • The malware aggressively attempts to disable macOS security features and prevents XProtect signature updates.
The Upside

If this development plays out positively, the discovery of the new XCSSET variant could lead to improved security measures for macOS developers, such as enhanced detection-evasion techniques and more robust security features. This could also lead to a decrease in the number of macOS users affected by the malware.

The Downside

The realistic downside risks or failure modes of this development include the potential for the malware to spread further and affect more macOS users, especially if the security measures are not implemented effectively. Additionally, the malware's ability to evade detection and its aggressive attempts to disable macOS security features make it a significant threat.

Originally reported at

bleepingcomputer.com

Discernion covers the story. Read the full piece at the source.

Tagsxcssetmacosxcodegithubmalwaresecurity

Author

Bill Toulas

Intelligence analysis by

Llama

Published

Aug 4, 2026

Source

bleepingcomputer.com

Share

Topics

xcssetmacosxcodegithubmalwaresecurity

Related

More from this desk

Aug 4·bleepingcomputer.com

77 Open VSX extensions found harvesting developer info

77 Open VSX extensions were found to be harvesting developer information, including system details and development environment metadata. The extensions, which were discovered by Manifold Security, did not access source code or credentials but did collect information that …

Aug 4·thehackernews.com

Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens

Greatness PhaaS, a commercial phishing-as-a-service toolkit, has added support for device code phishing, a rapidly growing cyber threat that bypasses Multi-Factor Authentication (MFA) and steals user tokens.

Aug 4·wired.com

Landmark Deal Would Officially Add Laser Weapons to US Army Arsenal

The US Army is poised to sign a contract to acquire and rapidly deploy a working laser weapon, the Enduring High Energy Laser, to defend its bases from drone attacks. This will be the first time the US military has committed to equipping its forces with laser weapons in s…

Aug 4·bleepingcomputer.com

Massive ChainDrop npm supply-chain attack infects hundreds of packages

A massive supply-chain attack has compromised over 1,300 packages on the Node Package Manager (npm) registry, including popular ones like Keyv and Cacheable. The attack, named 'ChainDrop', has been linked to a self-propagating malware that steals sensitive information and…