XCSSET macOS malware returns with first new version since 2022
ID: 996f4a23-953c-56fa-aa7d-a608feb1f402
STIX ID: report--996f4a23-953c-56fa-aa7d-a608feb1f402
Feed Name: The Register (Security)
Microsoft warns of a new XCSSET macOS malware variant that continues to target Xcode projects to infect developers and spread via repositories; it retains infostealing capabilities (wallets, Notes, app credentials) while adding more randomized obfuscation, updated persistence mechanisms (persisting via ~/.zshrc aliases and by replacing Launchpad on the Dock using a signed utility), and new payload placement strategies inside Xcode build settings. Although attacks have been limited so far and Microsoft provided no IoCs or hashes, the threat to developers and potential for repository-based propagation makes this a high-risk supply-chain style infection vector.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
