Seventeen: that is the number of distinct modules XCSSET can deploy after a four-stage infection chain, according to Palo Alto Networks Unit 42 — and the newest variant, v40, has been rewritten to reach deeper into macOS developer workflows and browsers.
How the malware reaches macOS developers
Unit 42 found the actor behind XCSSET is distributing the malware by compromising vulnerable Git repositories and injecting a downloader script into otherwise benign files inside Xcode projects. Developers who download and build those compromised projects become infected at build time; once resident, XCSSET can compromise every other Xcode project on the same machine and propagate further through shared source code. Researchers observed two distinct attack waves using this method in mid-April and in early May.
New capabilities in v40: Chrome hijacker and Telegram trojanizer
The updated XCSSET variant, labeled v40, introduces two new modules in addition to a large set of existing capabilities. Unit 42 describes a Chrome hijacker that places Chrome behind a malicious launcher and enables the Chrome DevTools Protocol (CDP) on a local port to fetch JavaScript from the attacker’s command-and-control (C2) infrastructure. That component can intercept web traffic — Unit 42 says this includes credentials, cookies, and MetaMask transactions — and manipulate transactions on the fly to divert payments. The hijacker also enables system command execution via a fileless reverse shell; Unit 42 notes Google already blocks that behavior in Chrome for Windows and is working to extend those protections to macOS.
The second new component is a “Telegram trojanizer,” which deletes the legitimate Telegram Desktop application on infected systems and replaces it with a malicious version that could be used to intercept victims’ communications. Unit 42 could not retrieve the malware’s encrypted configuration, so some details of the trojanizer’s exact functionality remain unknown.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scramble →What XCSSET already does: a multi-module infection chain
Before deploying its 17 modules, XCSSET follows a four-stage infection chain, Unit 42 reports. Across its module set the malware is capable of credential theft, keystroke logging, clipboard manipulation, browser hijacking, and data exfiltration. Past variants — noted in industry reporting — have at times included cryptocurrency-theft capabilities and even exploited zero-day vulnerabilities; Unit 42 places XCSSET activity back to at least 2021. Microsoft also warned in September 2025 about an XCSSET campaign that used compromised Xcode projects as a distribution mechanism.
Evasion, persistence, and attacks on macOS protections
Unit 42 highlights a series of deliberate detection-evasion measures in v40. The threat actor periodically recompiles the loader on the C2 server, uses separate encryption keys for inbound and outbound communications, and obfuscates function names, variables, and strings with build-unique ciphers. The malware aggressively attempts to disable macOS security controls — including XProtect, MRT, TCC, and Rapid Security Response — and terminates Apple’s CloudTelemetryService while preventing XProtect signature updates.
What this means for macOS developers, security teams, and open-source maintainers
- macOS developers: building third-party Xcode projects from untrusted or poorly protected Git repositories can produce immediate infection. Developers who share code or reuse local Xcode projects risk automatic propagation to other projects on the same machine.
- Security teams: Unit 42 recommends monitoring for anomalous AppleScript activity, unauthorized browser modifications, suspicious macOS defaults domains, and ad hoc-signed applications that bypass Gatekeeper; teams should also be alert to attempts to disable XProtect, MRT, TCC, or Rapid Security Response and to the termination of CloudTelemetryService.
- Open-source maintainers: compromised repositories are the distribution mechanism here — scanning open-source dependencies and hardening repository access can help prevent malicious downloader scripts from being injected into Xcode project files that downstream developers may build.
Unit 42’s findings paint a clear portrait: XCSSET v40 is targeted at the software development lifecycle itself, weaponizing the act of building code to seed infections and then expanding into browser- and messaging-focused theft and interception. With new evasion techniques and modules that reach into browsers and desktop messaging, the variant raises the stakes for anyone who downloads and builds third-party Xcode projects.
Read the original Unit 42-backed account at BleepingComputer: https://www.bleepingcomputer.com/news/security/new-xcsset-variant-targets-macos-devs-via-compromised-xcode-projects/




