logo

XCSSET v40 Infects Xcode Projects to Hijack Chrome and Trojanize Telegram on Macs

ID: 877e44e1-acc2-51bf-8f72-e9f2dbfb292f

STIX ID: report--877e44e1-acc2-51bf-8f72-e9f2dbfb292f

Feed Name: GBHackers

Threat Score
85/100

Date Published: 2026-08-03

Date Updated: 2026-08-03

Author: Mayura Kathir

ADMIRALTY:B6
...
...

XCSSET v40 is a highly evasive macOS supply-chain campaign that compromises Xcode projects and GitHub-hosted repos to infect developer workstations; it runs primarily in memory, uses polymorphic and per-build encryption, and dynamically loads modules for Chrome hijacking (via the Chrome DevTools Protocol), Telegram trojanizing, keylogging, clipboard theft and data exfiltration. The report details a four-phase execution pipeline, dual-key network encryption, anti-VM and macOS security sabotage, rotating C2 infrastructure with multiple domains/paths, and provides actionable IOCs for detection and blocking.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.